Loading market data...
← Back to CVE feed

CVE-2026-30996

HIGH CVSS 7.5 View on NVD ↗

Description

An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbitrary files from the system via a crafted GET request.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Apr 15, 2026 17:17 UTC Modified: Apr 15, 2026 19:16 UTC