Description
ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
No analysis available yet.
Remediation
Vendor Solution
Update version to v5.9 or latest
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52425 | ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7592-998bf-1.html |
|
History
Wed, 21 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-05-21T14:27:59.912Z
Reserved: 2023-11-16T03:49:45.971Z
Link: CVE-2023-48373
Updated: 2024-08-02T21:30:35.123Z
Status : Modified
Published: 2023-12-15T05:15:08.153
Modified: 2024-11-21T08:31:35.477
Link: CVE-2023-48373
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD