Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73xg-xcp8-j983

Опубликовано: 06 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' function call in '/api_vedo/video/preview'.

A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' function call in '/api_vedo/video/preview'.

EPSS

Процентиль: 17%
0.00055
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-98

Связанные уязвимости

CVSS3: 6.5
nvd
6 месяцев назад

A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' function call in '/api_vedo/video/preview'.

EPSS

Процентиль: 17%
0.00055
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-98