Show plain JSON{"id": "CVE-2019-19992", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N", "authentication": "SINGLE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.5, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 2.8}]}, "published": "2020-02-26T16:15:18.847", "references": [{"url": "https://www.seling.it/", "tags": ["Product"], "source": "cve@mitre.org"}, {"url": "https://www.seling.it/product/vam/", "tags": ["Product", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.seling.it/", "tags": ["Product"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.seling.it/product/vam/", "tags": ["Product", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-20"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to read XML files on the filesystem via the web interface. The PHP page /common/vam_editXml.php doesn't check the parameter that identifies the file name to be read. Thus, an attacker can manipulate the file name to access a potentially sensitive file within the filesystem."}, {"lang": "es", "value": "Se detect\u00f3 un problema en Selesta Visual Access Manager (VAM) versiones 4.15.0 hasta 4.29. Un usuario con credenciales validas es capaz de leer archivos XML en el sistema de archivos por medio de la interfaz web. El archivo /common/vam_editXml.php de la p\u00e1gina PHP no comprueba el par\u00e1metro que identifica el nombre del archivo a ser le\u00eddo. Por lo tanto, un atacante puede manipular el nombre del archivo para acceder a un archivo potencialmente confidencial dentro del sistema de archivos."}], "lastModified": "2024-11-21T04:35:48.223", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:seling:visual_access_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D1DDD534-B0DE-4F22-B69F-9971A8609AEF", "versionEndIncluding": "4.29.0", "versionStartIncluding": "4.15.0"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}