Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g6qh-7qh9-35p6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter.

There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter.

EPSS

Процентиль: 47%
0.0024
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
почти 6 лет назад

There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter.

EPSS

Процентиль: 47%
0.0024
Низкий

Дефекты

CWE-200