Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m49j-rg37-rq32

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.

mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.

EPSS

Процентиль: 74%
0.00842
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 20 лет назад

mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.

EPSS

Процентиль: 74%
0.00842
Низкий

Дефекты

CWE-287