Lucene search

K
cve[email protected]CVE-2021-42052
HistoryAug 16, 2022 - 11:15 p.m.

CVE-2021-42052

2022-08-1623:15:08
CWE-22
web.nvd.nist.gov
35
6
cve-2021-42052
ipesa e-flow
path traversal
web root directory
security vulnerability
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

62.1%

IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.

Affected configurations

NVD
Node
ipesae-flowMatch3.3.6
CPENameOperatorVersion
ipesa:e-flowipesa e-floweq3.3.6

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

62.1%

Related for CVE-2021-42052