Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7mv6-9483-r3cp

Опубликовано: 22 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.4

Описание

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data.

We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data.

We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

EPSS

Процентиль: 46%
0.00235
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 года назад

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

CVSS3: 9
fstec
около 1 года назад

Уязвимость приложения Notes Station для сетевых хранилищах QNAP, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю получить несанкционированный доступ к защищенной информации

EPSS

Процентиль: 46%
0.00235
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-918