Unauthorized File Download in Aseco Lietuva DVS Avilys Document Management System
CVE-2022-27192
7.5HIGH
What is CVE-2022-27192?
The Reporting module in the DVS Avilys document management system by Aseco Lietuva prior to version 3.5.58 contains a vulnerability that allows an unauthorized attacker to download files. This flaw enables an unauthenticated user to impersonate an administrator, leading to the exposure of sensitive administrative documents. This type of security weakness can jeopardize the integrity and confidentiality of the document management system, making it critical for users to update to the latest version to mitigate this risk.
