CVE-2022-39034

Publication date

2022-09-28 03:25:39

Family

twcert

State

PUBLISHED

Description

Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.