Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9w9h-4qfh-f6m6

Опубликовано: 09 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly.

An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly.

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly. NOTE: A community member states that this is not a CouchCMS vulnerability and that if /\<file> is accessible it is a web-server configuration issue.

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22