Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fgh-jjh6-cvr4

Опубликовано: 20 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 2
CVSS3: 7.5

Описание

Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.

Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.

EPSS

Процентиль: 49%
0.00259
Низкий

2 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20
CWE-639

Связанные уязвимости

nvd
около 1 года назад

Path Traversal vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.

EPSS

Процентиль: 49%
0.00259
Низкий

2 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20
CWE-639