Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6wmx-p4xj-5jr6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.

EPSS

Процентиль: 94%
0.13971
Средний

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.

EPSS

Процентиль: 94%
0.13971
Средний

Дефекты

CWE-20