Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r56-r7r5-55vj

Опубликовано: 07 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.

EPSS

Процентиль: 51%
0.00283
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-22

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 года назад

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.

EPSS

Процентиль: 51%
0.00283
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-22