Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-287x-c836-c4c9

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

EPSS

Процентиль: 81%
0.01625
Низкий

Связанные уязвимости

nvd
около 11 лет назад

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

EPSS

Процентиль: 81%
0.01625
Низкий