Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mx46-g635-gjjg

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containing sensitive credentials.

MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containing sensitive credentials.

EPSS

Процентиль: 53%
0.00303
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-260

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containing sensitive credentials.

EPSS

Процентиль: 53%
0.00303
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-260