CVE-2022-45184
EUVD-2022-4809214.11.2022, 08:15
The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege to create, delete, update, and display files outside of the configuration directory via a crafted HTTP request to particular endpoints in the web server. Patched Versions are 3.5.3 and 3.4.7.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ironmansoftware | powershell_universal | 3.0.0 ≤ 𝑥 < 3.4.7 |
| ironmansoftware | powershell_universal | 3.5.0 ≤ 𝑥 < 3.5.3 |
𝑥
= Vulnerable software versions