Security Advisory

CVE-2022-39034

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-09-28 03:25:39
Last updated 2025-05-21 14:51:03
Assigner twcert
State PUBLISHED

Description

Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.