vendor:
Archeevo
by:
Miguel Santareno
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: Archeevo
Affected Version From: < 5.0
Affected Version To: < 5.0
Patch Exists: NO
Related CWE:
CPE: a:keep:archeevo
Platforms Tested: Windows
2021
Archeevo 5.0 – Local File Inclusion
Unauthenticated user can exploit LFI vulnerability in file parameter.
Mitigation:
Implement input validation and output encoding to prevent malicious user from exploiting the vulnerability.