CVE-2022-39812

Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker can change the uploadDir parameter in a POST request (not possible using the GUI) to an arbitrary directory. Because the application does not check in which directory a file will be uploaded, an attacker can perform a variety of attacks that can result in unauthorized access to the server.
References
Link Resource
https://www.gruppotim.it/it/footer/red-team.html Exploit Third Party Advisory
https://www.gruppotim.it/it/footer/red-team.html Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:italtel:netmatch-s_ci:5.2.0-20211008:*:*:*:*:*:*:*

History

21 Nov 2024, 07:18

Type Values Removed Values Added
Summary
  • (es) Italtel NetMatch-S CI 5.2.0-20211008 permite el recorrido de ruta absoluto en NMSCI-WebGui/SaveFileUploader. Un usuario no autenticado puede cargar archivos en una ruta arbitraria. Un atacante puede cambiar el parámetro uploadDir en una solicitud POST (no es posible usando la GUI) a un directorio arbitrario. Debido a que la aplicación no verifica en qué directorio se cargará un archivo, un atacante puede realizar una variedad de ataques que pueden resultar en un acceso no autorizado al servidor.
References () https://www.gruppotim.it/it/footer/red-team.html - Exploit, Third Party Advisory () https://www.gruppotim.it/it/footer/red-team.html - Exploit, Third Party Advisory

Information

Published : 2023-01-27 22:15

Updated : 2024-11-21 07:18


NVD link : CVE-2022-39812

Mitre link : CVE-2022-39812

CVE.ORG link : CVE-2022-39812


JSON object : View

Products Affected

italtel

  • netmatch-s_ci
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')