Vulnerability Description
A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download arbitrary .dwg files from a remote server by specifying an absolute or relative path when invoking the affected DownloadDwg endpoint. An attack uses the path field to CaddemServiceJS/CaddemService.svc/rest/DownloadDwg.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Idearespa | Reftree | < 2021.09.17 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/166560/IdeaRE-RefTree-Path-Traversal.htmlThird Party AdvisoryVDB Entry
- https://www.idearespa.euProduct
- http://packetstormsecurity.com/files/166560/IdeaRE-RefTree-Path-Traversal.htmlThird Party AdvisoryVDB Entry
- https://www.idearespa.euProduct
FAQ
What is CVE-2022-27248?
CVE-2022-27248 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download arbitrary .dwg files from a remote server by specifying an absolute or relative pa...
How severe is CVE-2022-27248?
CVE-2022-27248 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-27248?
Check the references section above for vendor advisories and patch information. Affected products include: Idearespa Reftree.