CVE-2022-22790

SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unauthorized access to the file system. on the "Name" parameter the attacker can return to the root directory and open the host file. The path exposes sensitive files that users upload
References
Link Resource
https://www.gov.il/en/departments/faq/cve_advisories Third Party Advisory VDB Entry
https://www.gov.il/en/departments/faq/cve_advisories Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:synel:eharmony:8.0.2.3:*:*:*:*:*:*:*

History

21 Nov 2024, 06:47

Type Values Removed Values Added
References () https://www.gov.il/en/departments/faq/cve_advisories - Third Party Advisory, VDB Entry () https://www.gov.il/en/departments/faq/cve_advisories - Third Party Advisory, VDB Entry
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 5.6

Information

Published : 2022-01-28 20:15

Updated : 2024-11-21 06:47


NVD link : CVE-2022-22790

Mitre link : CVE-2022-22790

CVE.ORG link : CVE-2022-22790


JSON object : View

Products Affected

synel

  • eharmony
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')