Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3h35-4jmf-3v47

Опубликовано: 23 нояб. 2021
Источник: github
Github: Не прошло ревью

Описание

Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

EPSS

Процентиль: 61%
0.00407
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

EPSS

Процентиль: 61%
0.00407
Низкий

Дефекты

CWE-22