Description


A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.

Weaknesses



CWE-73


CWE-610

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.5 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-17T16:15:12.370Z

3 years ago

Last modified

2025-04-29T18:15:21.683Z

10 months ago