Description
Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission.
No analysis available yet.
Remediation
Vendor Solution
Update to: Personnel Attendance system ver. 3.4.0.0.3.12_20210525
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-22595 | Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission. |
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T17:44:17.942Z
Reserved: 2021-06-30T00:00:00.000Z
Link: CVE-2021-35962
No data.
Status : Modified
Published: 2021-07-16T16:15:11.023
Modified: 2024-11-21T06:12:50.670
Link: CVE-2021-35962
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD