ZeroHour

CVE-2022-22914

PoC
CVSS 3.1
7.5 high
EPSS
1%p71
Published
()
Modified
Description

An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in the upload directory via path traversal.

Vendors
ovidentia
Products
ovidentia
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.