PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request.
2018-12-17T19:29:02.750
2024-11-21T04:00:51.523
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ptc | thingworx_platform | ≤ 7.0.14 | Yes |
Application | ptc | thingworx_platform | < 7.0.0 | Yes |
Application | ptc | thingworx_platform | ≤ 7.1.18 | Yes |
Application | ptc | thingworx_platform | ≤ 7.2.21 | Yes |
Application | ptc | thingworx_platform | ≤ 7.3.18 | Yes |
Application | ptc | thingworx_platform | ≤ 7.4.14 | Yes |
Application | ptc | thingworx_platform | ≤ 8.0.12 | Yes |
Application | ptc | thingworx_platform | ≤ 8.1.8 | Yes |
Application | ptc | thingworx_platform | ≤ 8.2.5 | Yes |
Application | ptc | thingworx_platform | 8.3.0 | Yes |