go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Smartsoft SmartBPM.NET - Path Traversal

TVN ID TVN-202307006
CVE ID CVE-2023-37288
CVSS 6.5 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products SmartBPM.NET: 6.7
Description SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
Solution Contact SmartBPM.NET support team
Credit Alan Chung (DEVCORE)
Public Date 2023-09-19
Top