Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44vf-6vfg-98jr

Опубликовано: 15 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

EPSS

Процентиль: 61%
0.00409
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
23 дня назад

Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

EPSS

Процентиль: 61%
0.00409
Низкий

7.5 High

CVSS3

Дефекты

CWE-22