First published: Mon Jun 13 2022(Updated: )
Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter an arbitrary file on the server via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Generex Rccmd | <=4.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26041 is a directory traversal vulnerability in RCCMD 4.26 and earlier.
CVE-2022-26041 allows a remote authenticated attacker with administrative privilege to read or alter arbitrary files on the server.
CVE-2022-26041 has a severity level of medium with a CVSS score of 6.5.
To fix CVE-2022-26041, update RCCMD to version 4.27 or later.
More information about CVE-2022-26041 can be found at the following references: [1](https://jvn.jp/en/jp/JVN60801132/index.html), [2](https://www.generex.de/support/downloads/software/rccmd/update).