Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxf3-5gjm-vcfh

Опубликовано: 29 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to download and delete arbitrary system files to disrupt service.

Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to download and delete arbitrary system files to disrupt service.

EPSS

Процентиль: 81%
0.01468
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to download and delete arbitrary system files to disrupt service.

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость функции сбора файлов платформы бизнес-аналитики Smart eVision, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение, изменение или удаление данных

EPSS

Процентиль: 81%
0.01468
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22