← Back to CVE List

CVE-2022-24629

Published: 2023-05-29T21:15Z
Last Modified: 2025-01-14T18:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt