Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqff-mxpr-46m2

Опубликовано: 20 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.

Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.

EPSS

Процентиль: 59%
0.00388
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.

EPSS

Процентиль: 59%
0.00388
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20