Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-764p-g9xx-6qm8

Опубликовано: 20 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.

EPSS

Процентиль: 33%
0.00134
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-22
CWE-24

Связанные уязвимости

CVSS3: 5.8
nvd
10 месяцев назад

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.

EPSS

Процентиль: 33%
0.00134
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-22
CWE-24