CVE-2021-42052

IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.
References
Link Resource
https://nxnjz.net/2022/08/cve-2021-42052-full-disclosure/ Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:ipesa:e-flow:3.3.6:*:*:*:*:*:*:*

Information

Published : 2022-08-16 11:15

Updated : 2022-08-18 07:15


NVD link : CVE-2021-42052

Mitre link : CVE-2021-42052

Products Affected
No products.
CWE