Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fqf3-wwvm-vgr9

Опубликовано: 04 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.

EPSS

Процентиль: 33%
0.00128
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5
nvd
больше 3 лет назад

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.

EPSS

Процентиль: 33%
0.00128
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-22