CVE-2018-20092
https://notcve.org/view.php?id=CVE-2018-20092
PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request. PTC ThingWorx Platform hasta la versión 8.3.0 es vulnerable a un ataque de salto de directorio sobre los archivos ZIP mediante una petición POST. • https://www.doyler.net/security-not-included/ptc-thingworx-vulnerability https://www.ptc.com/en/documents/security/coordinated-vulnerability-disclosure/security-vulnerabilities • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2018-17218
https://notcve.org/view.php?id=CVE-2018-17218
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function. Se ha descubierto un problema desde las versiones 6.5 a la 8.2 de PTC ThingWorx Platform. Hay Cross-Site Scripting (XSS) reflejado en la función de búsqueda SQUEAL. • https://www.ptc.com/en/support/article?n=CS291004 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-17216
https://notcve.org/view.php?id=CVE-2018-17216
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users. Se ha descubierto un problema desde las versiones 6.5 a la 8.2 de PTC ThingWorx Platform. Hay una exposición de hashes de contraseñas a usuarios privilegiados. • https://www.ptc.com/en/support/article?n=CS291004 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-17217
https://notcve.org/view.php?id=CVE-2018-17217
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key. Se ha descubierto un problema desde las versiones 6.5 a la 8.2 de PTC ThingWorx Platform. Hay una clave de cifrado embebida. • https://www.ptc.com/en/support/article?n=CS291004 • CWE-798: Use of Hard-coded Credentials •