Back

HIGH

RONDS EPM version 1.19.5 does not properly validate the filename

Published Jan 17, 2023

Description

RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files.

Affected products

Remediation

Vendor solution

RONDS provides the software to users that purchase their products and recommends users upgrade the software to version 1.35.21.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jan 17, 2023
Updated Jan 16, 2025
Reserved Aug 18, 2022
CISA Vulnrichment
Updated Jan 16, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a