Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x42-9v2h-3jxc

Опубликовано: 29 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.

Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.

EPSS

Процентиль: 77%
0.01078
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.

EPSS

Процентиль: 77%
0.01078
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22