An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://tvn.twcert.org.tw/taiwanvn/TVN-201910007 | third party advisory |
https://www.chtsecurity.com/news/1179d48b-7609-4f67-9d7e-3bac2979c6ce | third party advisory |