An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lantime_firmware | Meinbergglobal | * | 6.24.029 (excluding) |
Lantime_firmware | Meinbergglobal | 7.0.0 (including) | 7.04.008 (excluding) |