Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54v4-2rmr-fh34

Опубликовано: 14 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.

Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.

EPSS

Процентиль: 83%
0.02037
Низкий

8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8
nvd
почти 4 года назад

Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.

EPSS

Процентиль: 83%
0.02037
Низкий

8 High

CVSS3

Дефекты

CWE-22