Cyber Posture

CVE-2023-42232

High

Published: 13 January 2025

Published
13 January 2025
Modified
17 April 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0064 70.7th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

Security Summary

CVE-2023-42232 is a directory traversal vulnerability affecting Pat Infinite Solutions HelpdeskAdvanced versions up to and including 11.0.33. The flaw exists in the Navigator/Index function, allowing attackers to access files outside the intended directory structure. It has a CVSS v3.1 base score of 7.5, rated as high severity due to its network accessibility, low attack complexity, lack of required privileges or user interaction, and significant confidentiality impact.

Unauthenticated attackers can exploit this vulnerability remotely over the network with low complexity and no privileges needed. Successful exploitation enables reading arbitrary files on the server, potentially exposing sensitive information such as configuration files, user data, or system details, though it does not impact integrity or availability.

Advisories reference a CVE list entry at https://gitlab.com/daniele_m/cve-list/-/blob/main/README.md, which documents the issue but provides no specific patch or mitigation details in the available information.

Details

CWE(s)
CWE-22

Affected Products

zucchetti
helpdeskadvanced
≤ 11.0.33

References