Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cgh5-9m3c-c3qx

Опубликовано: 12 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any directory accessible by the web server.

The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any directory accessible by the web server.

EPSS

Процентиль: 51%
0.0028
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any directory accessible by the web server.

EPSS

Процентиль: 51%
0.0028
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22