CVE-2022-38614EPSS p57.9%

CVE-2022-38614CVE-2022-38614

bpcbt / smartvista_cardgen

Description

An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.

Scoring

CVSS 7.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS0.94% probability of exploitation · percentile 57.9% · 2026-08-18T12:04:07Z
Last modified2026-07-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.