Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8w79-35vx-63xh

Опубликовано: 08 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.4

Описание

Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.

Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.

EPSS

Процентиль: 44%
0.00217
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.4
nvd
больше 1 года назад

Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.

EPSS

Процентиль: 44%
0.00217
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-89