Path traversal in Extensis Portfolio - CVE-2022-24254
Published: February 23, 2022
Extensis Portfolio
Detailed vulnerability description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in filenames inside zip archives. A remote user can upload a specially crafted zip archive and overwrite files on the system, leading to system compromise.