Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8pgq-587r-5r5g

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to download a database backup via a direct request.

Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to download a database backup via a direct request.

EPSS

Процентиль: 91%
0.0638
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
около 12 лет назад

Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to download a database backup via a direct request.

EPSS

Процентиль: 91%
0.0638
Низкий

Дефекты

CWE-200