CVE-2022-4511: RainyGao DocSys path traversal
A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unknown functionality of the component com.DocSystem.controller.UserController#getUserImg. The manipulation leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215851.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4511?
CVE-2022-4511 is classified as a critical vulnerability.
How do I fix CVE-2022-4511?
To fix CVE-2022-4511, ensure that proper input validation and access controls are implemented in the UserController component.
What are the implications of exploiting CVE-2022-4511?
Exploiting CVE-2022-4511 can lead to unauthorized access to sensitive files through path traversal.
Which versions of DocSys are affected by CVE-2022-4511?
All versions of Docsys Project Docsys are potentially affected by CVE-2022-4511.
What is the attack vector for CVE-2022-4511?
The attack vector for CVE-2022-4511 involves manipulating the getUserImg functionality to perform path traversal.