The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://lt.asseco.com/sprendimai/dokumentu-valdymas/dvs-avilys/ | product vendor advisory |
https://github.com/transcendent-group/advisories/blob/main/CVE-2022-27192.md | third party advisory |