Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pw32-4hxv-cxrf

Опубликовано: 04 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.

Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.

EPSS

Процентиль: 42%
0.00204
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.

EPSS

Процентиль: 42%
0.00204
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22