Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28mp-g2wm-23p3

Опубликовано: 31 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6

Описание

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

EPSS

Процентиль: 53%
0.00302
Низкий

6 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.5
nvd
около 2 лет назад

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

EPSS

Процентиль: 53%
0.00302
Низкий

6 Medium

CVSS3

Дефекты

CWE-22