Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhv3-q37g-rjx5

Опубликовано: 29 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10

Описание

Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection.  Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker.

This issue affects SparkView: before build 1127.

Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection.  Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker.

This issue affects SparkView: before build 1127.

EPSS

Процентиль: 31%
0.00378
Низкий

10 Critical

CVSS4

Дефекты

CWE-23

Связанные уязвимости

nvd
2 месяца назад

Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection.  Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker. This issue affects SparkView: before build 1127.

EPSS

Процентиль: 31%
0.00378
Низкий

10 Critical

CVSS4

Дефекты

CWE-23