Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jx4-4hmg-8h59

Опубликовано: 04 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.

EPSS

Процентиль: 59%
0.00379
Низкий

7.2 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 лет назад

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.

EPSS

Процентиль: 59%
0.00379
Низкий

7.2 High

CVSS3

Дефекты

CWE-22