CVE-2022-45269
Linx Sphere - Directory Traversal
Record summary
CVE-2022-45269 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryHIGHLinx Sphere - Directory TraversalCVSS 7.5
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.
Impact
Unauthenticated attackers can exploit path traversal to read arbitrary files from the server, potentially accessing sensitive configuration files, credentials, and application source code.
Remediation
Update Linx Sphere to a version newer than 7.35.ST15 that properly validates file paths and prevents directory traversal attacks.
Source: ProjectDiscovery