Sysaid - CWE-552: Files or Directories Accessible to External Parties
CVE-2023-32226
8.3HIGH
What is CVE-2023-32226?
Authenticated users in Sysaid can exploit a weakness that permits the unauthorized access and exfiltration of files from the server. This vulnerability arises due to inadequate restrictions on file access, allowing users with authentication to retrieve data that should remain private. The lack of proper security measures poses a risk of sensitive data being leaked, potentially impacting confidentiality and integrity.
Affected Version(s)
Sysaid All versions < 23.2.14 b18