Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wfc-7v23-c2vf

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1

Описание

STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files like /etc/passwd.

STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files like /etc/passwd.

EPSS

Процентиль: 41%
0.00187
Низкий

7.1 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

nvd
около 2 месяцев назад

STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files like /etc/passwd.

EPSS

Процентиль: 41%
0.00187
Низкий

7.1 High

CVSS4

Дефекты

CWE-22