Impact
Improper limitation of a pathname to a restricted directory allows an attacker to traverse directory boundaries and read or modify files outside the intended scope. This flaw can expose configuration files, sensitive data, or allow further exploitation, compromising confidentiality and integrity. It is classified as CWE‑22, a common path‑traversal weakness.
Affected Systems
The affected product is HAVELSAN Inc.'s Liman MYS. Vulnerable versions are 2.3.2 through the release prior to 2.3.4‑1124. Systems must be upgraded to version 2.3.4‑1124 or later to eliminate the issue.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, implying limited known exploitation. Based on the disclosure, the flaw is likely exploitable via the application interface when an attacker can supply a crafted filepath; authentication requirements are not specified, so the attack vector is inferred and may require internal or network access to the affected system.
OpenCVE Enrichment