Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvgf-2rf7-wrx9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Froxlor Information Disclosure

An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, because of _createUserdataConf in install/lib/class.FroxlorInstall.php.

Пакеты

Наименование

froxlor/froxlor

composer
Затронутые версииВерсия исправления

< 0.10.14

0.10.14

EPSS

Процентиль: 34%
0.00139
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.1
nvd
почти 6 лет назад

An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, because of _createUserdataConf in install/lib/class.FroxlorInstall.php.

CVSS3: 6.1
debian
почти 6 лет назад

An issue was discovered in Froxlor before 0.10.14. It created files wi ...

EPSS

Процентиль: 34%
0.00139
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-20