A vulnerability has been identified in IP3 NetAccess, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is due to an input validation error in the "portalgroups/portalgroups/getfile.cgi" script that does not validate the "filename" parameter, which could be exploited by malicious users to access and disclose the contents of arbitrary files.
Vulnerable Products
Vulnerable Software: IP3 NetAccess versions prior to 4.1.9.6