CVE-2022-50890

Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. Attackers can exploit the vulnerability by crafting GET requests with directory traversal sequences to access restricted system directories on the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:skyjos:owlfiles:12.0.1:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:ipados:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 23:15

Updated : 2026-01-29 00:43


NVD link : CVE-2022-50890

Mitre link : CVE-2022-50890

CVE.ORG link : CVE-2022-50890


JSON object : View

Products Affected

skyjos

  • owlfiles

apple

  • ipados
  • iphone_os
  • tvos
  • visionos
  • macos
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')