Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3ccj-82gj-65cg

Опубликовано: 08 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directory and overwriting files in arbitrary locations. This vulnerability has a high impact on the integrity and availability of the application with no impact on confidentiality.

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directory and overwriting files in arbitrary locations. This vulnerability has a high impact on the integrity and availability of the application with no impact on confidentiality.

EPSS

Процентиль: 15%
0.0005
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.8
nvd
7 месяцев назад

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directory and overwriting files in arbitrary locations. This vulnerability has a high impact on the integrity and availability of the application with no impact on confidentiality.

CVSS3: 5.8
fstec
7 месяцев назад

Уязвимость утилиты сжатия и распаковки файлов SAPCAR, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записывать произвольные файлы

EPSS

Процентиль: 15%
0.0005
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-22