Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-26r2-6q54-995j

Опубликовано: 20 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.

Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.

EPSS

Процентиль: 43%
0.00205
Низкий

8.8 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 8.8
nvd
почти 4 года назад

Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.

EPSS

Процентиль: 43%
0.00205
Низкий

8.8 High

CVSS3

Дефекты

CWE-345