First published: Wed Jun 07 2023(Updated: )
By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
PTC Vuforia Studio | <9.9 | |
PTC Vuforia Studio: all versions prior to 9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-29152.
The severity of CVE-2023-29152 is high, with a severity value of 8.1.
By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.
PTC Vuforia Studio versions up to 9.9 are affected by CVE-2023-29152.
To fix CVE-2023-29152, it is recommended to apply the latest security updates or patches provided by the software vendor.