CVE-2022-39034
EUVD-2022-4158028.09.2022, 04:15
Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lcnet | smart_evision | 2022.03.21 |
𝑥
= Vulnerable software versions