vendor:
Omnia MPX
by:
Momen Eldawakhly
8.8
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Omnia MPX
Affected Version From: 1.5.0+r1
Affected Version To: 1.5.0+r1
Patch Exists: YES
Related CWE:
CPE: a:telos_alliance:omnia_mpx:1.5.0+r1
Platforms Tested: MacOS
2022
Omnia MPX 1.5.0+r1 – Path Traversal
A path traversal vulnerability exists in Omnia MPX 1.5.0+r1 which allows an attacker to access sensitive files and user database. By sending a crafted HTTP request to the vulnerable server, an attacker can access the files and user database stored in the server.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their systems to the latest version.