CVE-2022-24581

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
02/06/2022
Last modified:
11/06/2022

Description

ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aceware:aceweb_online_portal:*:*:*:*:*:*:*:* 3.5.065 (excluding)