Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9v7f-rj28-9x3v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.

In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.

EPSS

Процентиль: 68%
0.00569
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 7.7
nvd
больше 3 лет назад

In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.

EPSS

Процентиль: 68%
0.00569
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-494