CVE-2022-39037: FLOWRING Agentflow BPM - Path Traversal
Published Nov 10, 2022
·Updated
Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
Affected Software
1 affected component
Flowring Agentflow=4.0.0.1183.552
Remediation
Information
Contact tech support from FLOWRING
Event History
Nov 10, 2022
CVE Published
via MITRE·02:20 AM
Data Sourced
via MITRE·02:20 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-39037?
CVE-2022-39037 has been classified with a moderate severity level due to its ability to allow unauthenticated remote attackers to access sensitive files.
2
How do I fix CVE-2022-39037?
To fix CVE-2022-39037, update to the latest version of Agentflow that patches the path traversal vulnerability.
3
What impact can CVE-2022-39037 have on my system?
CVE-2022-39037 can lead to unauthorized file downloads, potentially exposing sensitive information to attackers.
4
Is CVE-2022-39037 exploitable remotely?
Yes, CVE-2022-39037 is exploitable remotely by unauthenticated attackers.
5
What versions of Agentflow are affected by CVE-2022-39037?
CVE-2022-39037 specifically affects Agentflow version 4.0.0.1183.552.