Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m64-g8r6-3ghw

Опубликовано: 13 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

EPSS

Процентиль: 35%
0.00143
Низкий

8.7 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

nvd
3 месяца назад

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

EPSS

Процентиль: 35%
0.00143
Низкий

8.7 High

CVSS4

Дефекты

CWE-22