An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-02-04 21:15
Updated : 2024-02-13 00:38
NVD link : CVE-2021-46902
Mitre link : CVE-2021-46902
CVE.ORG link : CVE-2021-46902
JSON object : View
Products Affected
meinbergglobal
- lantime_firmware
CWE