Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhhf-pcpv-xqqq

Опубликовано: 11 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.

An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.

EPSS

Процентиль: 57%
0.00349
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.

EPSS

Процентиль: 57%
0.00349
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611