Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvhh-hg59-vfxx

Опубликовано: 28 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024. Impacted is the function zfilev2_api_SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. The manipulation results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024. Impacted is the function zfilev2_api_SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. The manipulation results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

EPSS

Процентиль: 62%
0.00435
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74
CWE-77

Связанные уязвимости

CVSS3: 6.3
nvd
около 1 месяца назад

A vulnerability was found in ZSPACE Z4Pro+ 1.0.0440024. Impacted is the function zfilev2_api_SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. The manipulation results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

EPSS

Процентиль: 62%
0.00435
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74
CWE-77