Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j3r-j4h7-v6hh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.

The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.

EPSS

Процентиль: 96%
0.21249
Средний

Связанные уязвимости

CVSS3: 4.3
nvd
около 6 лет назад

The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.

EPSS

Процентиль: 96%
0.21249
Средний