Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pc9q-654c-78w3

Опубликовано: 02 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File Write and Delete.

SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File Write and Delete.

EPSS

Процентиль: 56%
0.00342
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.1
nvd
больше 3 лет назад

SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File Write and Delete.

EPSS

Процентиль: 56%
0.00342
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-787