Back

HIGH

TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Read through Path Traversal

Published Oct 14, 2024

Description

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

Affected products

Remediation

Vendor solution

Update to version v14.0.0 or later.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Oct 14, 2024
Updated Oct 15, 2024
Reserved Oct 14, 2024
CISA Vulnrichment
Updated Oct 15, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner twcert
Published Oct 14, 2024
Updated Oct 15, 2024
Exploited since n/a
EUVD-2024-50212