vendor:
Virtual Reception
by:
Spinae
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Virtual Reception
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: CVE-2023-25289
CPE: a:virtual_reception:virtual_reception:1.0
Platforms Tested: all
2021
Virtual Reception v1.0 – Web Server Directory Traversal
We discovered the web server of the Virtual Reception appliance is prone to an unauthenticated directory traversal vulnerability. This allows an attacker to traverse outside the server root directory by specifying files at the end of a URL request. This is a NUC5i5RY. A user called 'receptie' exists on the Windows system. The appliance also keeps a log of the visitors that register at the entrance.
Mitigation:
Ensure that the web server is properly configured to prevent directory traversal attacks.