Path traversal in ProVision - #VU50174
Published: February 1, 2021
ProVision
STVS SA
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in "archive.rb" script. A remote authenticated attacker can send a specially crafted HTTP request and create or overwrite arbitrary files on the system.