Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23hm-6gvp-w3w5

Опубликовано: 21 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

EPSS

Процентиль: 81%
0.01587
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22

EPSS

Процентиль: 81%
0.01587
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22