CVE-2024-3122

CVSS v3 Score
4.9
Medium

Vulnerability Description

CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.

CVSS:4.9(Medium)

A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifi...

CWE-232022
CVSS:4.9(Medium)

Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on ...

CWE-232022
CVSS:4.9(Medium)

Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.

CWE-232022
CVSS:4.9(Medium)

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers,...

CWE-232024
CVSS:4.9(Medium)

A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or ...

CWE-232024
CVSS:4.9(Medium)

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root dire...

CWE-232024