Record summary

CVE-2022-38794 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHZaver - Local File InclusionCVSS 7.5

Zaver through 2020-12-15 is vulnerable to local file inclusion via the GET /.. substring.

Impact

This vulnerability can lead to unauthorized access, data leakage, and remote code execution.

Remediation

To remediate this vulnerability, ensure that user input is properly validated and sanitized before being used in file inclusion operations.

WeaknessesCWE-22
Authorspikpikcu
Template tagscvecve2022lfizaverzaver_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:zaver_project:zaver:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2