Vulnerabilities > Idearespa

DATE CVE VULNERABILITY TITLE RISK
2022-04-03 CVE-2022-27248 Path Traversal vulnerability in Idearespa Reftree
A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download arbitrary .dwg files from a remote server by specifying an absolute or relative path when invoking the affected DownloadDwg endpoint.
network
low complexity
idearespa CWE-22
4.0
2022-04-03 CVE-2022-27249 Unrestricted Upload of File with Dangerous Type vulnerability in Idearespa Reftree
An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted aspx file to the web root, and then visiting the URL for this aspx resource.
network
low complexity
idearespa CWE-434
critical
9.0