Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2f74-23cq-pjc6

Опубликовано: 28 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.

An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.

EPSS

Процентиль: 67%
0.01318
Низкий

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.

EPSS

Процентиль: 67%
0.01318
Низкий

Дефекты

CWE-668