vendor:
Conacwin
by:
Bryan Rodriguez Martin AKA tr3mb0
9.3
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: Conacwin
Affected Version From: 3.7.1.2
Affected Version To: 3.7.1.2
Patch Exists: YES
Related CWE: N/A
CPE: a:setelsa_security:conacwin:3.7.1.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Setelsa Conacwin 3.7.1.2 – Local File Inclusion
A local file inclusion vulnerability exists in Setelsa Conacwin 3.7.1.2, which allows an attacker to include a local file on the web server. This can be exploited by sending a specially crafted HTTP request containing directory traversal characters (e.g. '../') to the vulnerable server. This can allow an attacker to gain access to sensitive information or execute arbitrary code on the server.
Mitigation:
The recommendation from the vendor is to update to the last version.