CVE-2021-42052

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
16/08/2022
Last modified:
18/08/2022

Description

IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ipesa:e-flow:3.3.6:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools