CVE-2022-22701
EUVD-2022-2784410.01.2022, 14:12
PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| partkeepr | partkeepr | 𝑥 ≤ 1.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration