Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7jv-x682-58fv

Опубликовано: 27 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the display of unintended files. Any file accessible to the Kurmi user account could be displayed, e.g., configuration files with information such as the database password.

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the display of unintended files. Any file accessible to the Kurmi user account could be displayed, e.g., configuration files with information such as the database password.

EPSS

Процентиль: 70%
0.00645
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.9
nvd
около 1 года назад

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the display of unintended files. Any file accessible to the Kurmi user account could be displayed, e.g., configuration files with information such as the database password.

EPSS

Процентиль: 70%
0.00645
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22