Description
Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.
No analysis available yet.
Remediation
Vendor Solution
Contact tech support from Smart eVision Information Technology Inc.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-41580 | Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-6571-fc930-1.html |
|
History
Wed, 21 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-05-21T14:51:03.109Z
Reserved: 2022-08-30T00:00:00.000Z
Link: CVE-2022-39034
Updated: 2024-08-03T11:10:32.494Z
Status : Modified
Published: 2022-09-28T04:15:14.977
Modified: 2024-11-21T07:17:25.100
Link: CVE-2022-39034
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD