github.com
https://github.com/zyearn/zaver/issues/22 CVE-2022-38794
HIGHNuclei
Zaver - Local File Inclusion
Record summary
CVE-2022-38794 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHZaver - Local File InclusionCVSS 7.5
Zaver through 2020-12-15 is vulnerable to local file inclusion via the GET /.. substring.
Impact
This vulnerability can lead to unauthorized access, data leakage, and remote code execution.
Remediation
To remediate this vulnerability, ensure that user input is properly validated and sanitized before being used in file inclusion operations.
WeaknessesCWE-22
Authorspikpikcu
Template tagscvecve2022lfizaverzaver_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:zaver_project:zaver:*:*:*:*:*:*:*:*
https://github.com/zyearn/zaver/issues/22 https://nvd.nist.gov/vuln/detail/CVE-2022-38794 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates https://github.com/Henry4E36/POCS
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-38794