Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.
References
Link | Resource |
---|---|
https://know.bishopfox.com/advisories | Third Party Advisory |
https://know.bishopfox.com/advisories/solismed-critical | Exploit Third Party Advisory |
https://www.solismed.com/ | Product |
https://know.bishopfox.com/advisories | Third Party Advisory |
https://know.bishopfox.com/advisories/solismed-critical | Exploit Third Party Advisory |
https://www.solismed.com/ | Product |
Configurations
History
21 Nov 2024, 04:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://know.bishopfox.com/advisories - Third Party Advisory | |
References | () https://know.bishopfox.com/advisories/solismed-critical - Exploit, Third Party Advisory | |
References | () https://www.solismed.com/ - Product |
Information
Published : 2019-12-12 14:15
Updated : 2024-11-21 04:30
NVD link : CVE-2019-16246
Mitre link : CVE-2019-16246
CVE.ORG link : CVE-2019-16246
JSON object : View
Products Affected
intesync
- solismed
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')