CVE-2022-44016 Information
Dec 26, 2022
cve
Description
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing an API call: /DS/LM_API/api/ConfigurationService/GetImages with an ‘\ImagesPath:\C:\' value.