Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q772-4845-474h

Опубликовано: 07 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.

BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.

EPSS

Процентиль: 90%
0.05486
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.

EPSS

Процентиль: 90%
0.05486
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22