Vulnerabilities
Vulnerable Software
Stvs:  >> Provision  >> 5.7  Security Vulnerabilities
STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.
CVSS Score
6.9
EPSS Score
0.0
Published
2025-12-09
STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files like /etc/passwd.
CVSS Score
7.1
EPSS Score
0.002
Published
2025-12-09


Contact Us

Shodan ® - All rights reserved