Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2gqp-7qqf-5rcq

Опубликовано: 25 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/". A malicious actor could identify the existence of users by requesting share information on specified share paths.

All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/". A malicious actor could identify the existence of users by requesting share information on specified share paths.

EPSS

Процентиль: 47%
0.00237
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
почти 4 года назад

All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths.

EPSS

Процентиль: 47%
0.00237
Низкий

Дефекты

CWE-200