Allegra downloadAttachmentGlobal Directory Traversal Information Disclosure Vulnerability
CVE-2023-52334
6.5MEDIUM
What is CVE-2023-52334?
The Allegra application developed by TrackPlus contains a directory traversal vulnerability that allows remote attackers to disclose sensitive information from the affected systems. The flaw specifically resides in the 'downloadAttachmentGlobal' action, where user-supplied paths are not adequately validated prior to being utilized in file operations. This oversight enables attackers, even those who have authenticated, to exploit the issue and potentially expose stored credentials, which could lead to further unauthorized access and compromise of the affected installations.
Affected Version(s)
Allegra 7.5.0 build 29
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
