Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hx2g-vqw8-rh9r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can login as "admin", then to modify specific shell file to achieve remote code execution(RCE) on the hosting server.

A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can login as "admin", then to modify specific shell file to achieve remote code execution(RCE) on the hosting server.

EPSS

Процентиль: 90%
0.05529
Низкий

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can login as "admin", then to modify specific shell file to achieve remote code execution(RCE) on the hosting server.

EPSS

Процентиль: 90%
0.05529
Низкий

Дефекты

CWE-94