Remote Attackers Can Read Arbitrary Files on System via Mobile One Time Password Flaw
CVE-2024-3122
4.9MEDIUM
What is CVE-2024-3122?
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
Affected Version(s)
Mobile One Time Password earlier <= 3.11.2
