CVE-2022-38614

HIGH

SmartVista Cardgen <3.28.0 - Path Traversal

Title source: llm
STIX 2.1

Description

An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
http://bpcbt.com
Not Applicable x_refsource_misc
http://smartvista.com

Scores

CVSS v3 7.5
EPSS 0.0103
EPSS Percentile 59.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
bpcbt/smartvista_cardgen 3.28.0
Published Sep 09, 2022
Tracked Since Feb 18, 2026