Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43g8-79x3-j898

Опубликовано: 15 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Unrestricted access to predictable file paths in hov/jobfair

An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extension fails to protect or obfuscate filenames of uploaded files. This allows unauthenticated users to download files with sensitive data by simply guessing the filename of uploaded files (e.g., uploads/tx_jobfair/cv.pdf).

Пакеты

Наименование

hov/jobfair

composer
Затронутые версииВерсия исправления

< 1.0.13

1.0.13

Наименование

hov/jobfair

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.2

2.0.2

EPSS

Процентиль: 80%
0.01398
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extension fails to protect or obfuscate filenames of uploaded files. This allows unauthenticated users to download files with sensitive data by simply guessing the filename of uploaded files (e.g., uploads/tx_jobfair/cv.pdf).

EPSS

Процентиль: 80%
0.01398
Низкий

7.5 High

CVSS3

Дефекты

CWE-200