Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99fr-77xr-r9f4

Опубликовано: 20 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input. Attackers can traverse directories and access sensitive files outside the intended web root.

Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input. Attackers can traverse directories and access sensitive files outside the intended web root.

EPSS

Процентиль: 98%
0.5156
Средний

8.7 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

nvd
6 месяцев назад

Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input. Attackers can traverse directories and access sensitive files outside the intended web root.

EPSS

Процентиль: 98%
0.5156
Средний

8.7 High

CVSS4

Дефекты

CWE-22