CVE-2022-34002

MEDIUM

PDS Vista 7 < 7.1.7.2 - Authenticated Local File Inclusion via Document Parameter

Title source: llm
STIX 2.1

Description

The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows an low-privileged authenticated attacker to leak the configuration files and source code of the web application.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0089
EPSS Percentile 54.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
pdssoftware/pds_vista_7 < 7.1.7.2
Published Sep 16, 2022
Tracked Since Feb 18, 2026