Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Softsul
Softsul sac-nfe |
|
| Vendors & Products |
Softsul
Softsul sac-nfe |
Wed, 15 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in SAC‑NFe v2.0.02 download.php Allows Arbitrary File Read | |
| Weaknesses | CWE-200 |
Wed, 15 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Wed, 15 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbitrary files from the system via a crafted GET request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-15T18:05:30.972Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-30996
Updated: 2026-04-15T18:05:27.061Z
Status : Deferred
Published: 2026-04-15T17:17:04.443
Modified: 2026-04-27T19:18:46.690
Link: CVE-2026-30996
No data.
OpenCVE Enrichment
Updated: 2026-04-16T09:12:52Z