CVE-2022-46309

CVSS V2 None CVSS V3 None
Description
Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to access arbitrary system files.
Overview
  • CVE ID
  • CVE-2022-46309
  • Assigner
  • twcert@cert.org.tw
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-03T03:15:10
  • Last Modified Date
  • 2023-01-10T14:31:22
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:vitalsesp:vitals_esp:*:*:*:*:*:*:*:* 1 OR 3.0.8 6.2.0
References
History
Created Old Value New Value Data Type Notes
2023-01-03 03:15:40 Added to TrackCVE
2023-01-03 03:15:41 Weakness Enumeration new
2023-01-03 14:13:52 2023-01-03T13:26:12 CVE Modified Date updated
2023-01-03 14:13:52 Received Awaiting Analysis Vulnerability Status updated
2023-01-06 20:18:19 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-10 15:16:51 2023-01-10T14:31:22 CVE Modified Date updated
2023-01-10 15:16:51 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-10 15:16:52 CPE Information updated