Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4h3-3v97-vpwx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.

EPSS

Процентиль: 74%
0.00841
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.

EPSS

Процентиль: 74%
0.00841
Низкий

Дефекты

CWE-787