vendor:
eMerge E3
by:
LiquidWorm
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: eMerge E3
Affected Version From: 1.00-06
Affected Version To: 1.00-06
Patch Exists: YES
Related CWE: CVE-2019-7254
CPE: a:linear_solutions:emerge_e3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: NA
2018
eMerge E3 1.00-06 – Unauthenticated Directory Traversal
eMerge E3 1.00-06 is vulnerable to an unauthenticated directory traversal vulnerability. An attacker can send a specially crafted HTTP request to the vulnerable server to traverse the directory and read sensitive files. This vulnerability is due to insufficient input validation of user-supplied data. An attacker can exploit this vulnerability to gain access to sensitive information such as system files, passwords, and other confidential data.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update their systems to the latest version.