The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://lt.asseco.com/sprendimai/dokumentu-valdymas/dvs-avilys/ | vendor advisory product |
https://github.com/transcendent-group/advisories/blob/main/CVE-2022-27192.md | third party advisory |