PoC Index

CVE-2022-28478

MEDIUM 6.5EPSS 1.5%

SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVSS v2.0
5.5 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
EPSS
1.51% chance of exploitation in the next 30 days, 73th percentile
Published
2022-06-06
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related