CVE-2022-48482: Path Traversal
Published May 2, 2023
·Updated
3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.
Affected Software
4 affected components
All of the following
3CX 3CX<18.0.2.315
Microsoft Windows
3CX 3CX<18.0.2.315
Microsoft Windows
Event History
May 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
05:15 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2022-48482.
2
What is the severity level of CVE-2022-48482?
CVE-2022-48482 has a severity level of 7.5 (high).
3
What is affected by CVE-2022-48482?
3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows is affected by CVE-2022-48482.
4
How can unauthenticated remote attackers exploit CVE-2022-48482?
Unauthenticated remote attackers can exploit CVE-2022-48482 by reading certain files via /Electron/download directory traversal.
5
What kind of files can be accessed by exploiting CVE-2022-48482?
By exploiting CVE-2022-48482, attackers can potentially access files containing credentials, full backups, call recordings, and chat logs.