Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4rv-5346-m4jx

Опубликовано: 06 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.8
CVSS3: 8.8

Описание

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations.

We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations.

We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later

EPSS

Процентиль: 97%
0.40675
Средний

6.8 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later

EPSS

Процентиль: 97%
0.40675
Средний

6.8 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-59