Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhm6-2hxr-6fv7

Опубликовано: 28 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7

Описание

A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this vulnerability to overwrite reports including user projects.

A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this vulnerability to overwrite reports including user projects.

EPSS

Процентиль: 34%
0.00139
Низкий

7 High

CVSS4

Дефекты

CWE-200

Связанные уязвимости

nvd
около 1 года назад

A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this vulnerability to overwrite reports including user projects.

EPSS

Процентиль: 34%
0.00139
Низкий

7 High

CVSS4

Дефекты

CWE-200