CVE-2022-46309

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
03/01/2023
Last modified:
10/01/2023

Description

Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to access arbitrary system files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vitalsesp:vitals_esp:*:*:*:*:*:*:*:* 3.0.8 (including) 6.2.0 (including)


References to Advisories, Solutions, and Tools