Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pg7f-8r86-68j5

Опубликовано: 14 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

EPSS

Процентиль: 49%
0.0026
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

EPSS

Процентиль: 49%
0.0026
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20