Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38wv-wfx6-3cx2

Опубликовано: 23 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 4

Описание

YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:/// protocol.

YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:/// protocol.

EPSS

Процентиль: 18%
0.00058
Низкий

6.9 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 4
nvd
15 дней назад

YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:/// protocol.

EPSS

Процентиль: 18%
0.00058
Низкий

6.9 Medium

CVSS4

4 Medium

CVSS3

Дефекты

CWE-434