Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-39jq-p97c-g7gh

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.

Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.

EPSS

Процентиль: 36%
0.00147
Низкий

7.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.1
nvd
около 8 лет назад

Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.

EPSS

Процентиль: 36%
0.00147
Низкий

7.1 High

CVSS3

Дефекты

CWE-22