Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrvj-5hh7-vf4w

Опубликовано: 07 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.

SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.

EPSS

Процентиль: 79%
0.01278
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.

EPSS

Процентиль: 79%
0.01278
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22