CVE-2024-36427
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
29/05/2024
Last modified:
27/09/2024
Description
The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to read or write to server files via a crafted file request. This can allow code execution via a .xview file.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH