Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hcc-5pm7-xc33

Опубликовано: 02 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.

EPSS

Процентиль: 67%
0.00544
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.

EPSS

Процентиль: 67%
0.00544
Низкий

7.5 High

CVSS3

Дефекты

CWE-22