Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h45j-h84g-x6fh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.

An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.

EPSS

Процентиль: 69%
0.00597
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
больше 4 лет назад

An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.

EPSS

Процентиль: 69%
0.00597
Низкий

Дефекты

CWE-22