CVE-2024-8778

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
16/09/2024
Last modified:
20/09/2024

Description

OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:syscomgo:omflow:*:*:*:*:*:*:*:* 1.1.6.0 (including) 1.2.1.3 (excluding)