Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the ‘/pictory/php/getFileList.php’ endpoint in the ‘dir’ parameter.
This Cyber News was published on www.tenable.com. Publication date: Mon, 10 Feb 2025 15:41:02 +0000