Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jcp-j236-2qqc

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

EPSS

Процентиль: 53%
0.00304
Низкий

7.6 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.2
nvd
больше 3 лет назад

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

EPSS

Процентиль: 53%
0.00304
Низкий

7.6 High

CVSS3

Дефекты

CWE-434