Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h7w4-2vfc-fx35

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php.

Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php.

EPSS

Процентиль: 45%
0.00224
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.5
nvd
больше 8 лет назад

Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php.

EPSS

Процентиль: 45%
0.00224
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-434