Record summary

CVE-2022-45269 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHLinx Sphere - Directory TraversalCVSS 7.5

A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

Impact

Unauthenticated attackers can exploit path traversal to read arbitrary files from the server, potentially accessing sensitive configuration files, credentials, and application source code.

Remediation

Update Linx Sphere to a version newer than 7.35.ST15 that properly validates file paths and prevents directory traversal attacks.

WeaknessesCWE-22
Authorsrobotshell
Template tagscvecve2022linxlfiscsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:gmaolinx:linx_sphere:7.35.st15:*:*:*:*:*:*:*
FOFA: SCS.Web.Server.SPI/1.0

Source: ProjectDiscovery

References

2