← Back to CVE List

CVE-2022-1359

Published: 2022-05-17T21:15Z
Last Modified: 2024-11-21T06:40Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt