IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.
References
Link | Resource |
---|---|
https://nxnjz.net/2022/08/cve-2021-42052-full-disclosure/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-08-16 16:15
Updated : 2022-08-18 12:15
NVD link : CVE-2021-42052
Mitre link : CVE-2021-42052
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
ipesa
- e-flow