Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qggm-xmg7-pqpf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

** DISPUTED ** BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error. NOTE: This has been disputed with the following reasoning: "The issue reported requires full developer level access to the content management system where cross site scripting is not an issue -- you already have full control of the CMS including running arbitrary PHP."

** DISPUTED ** BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error. NOTE: This has been disputed with the following reasoning: "The issue reported requires full developer level access to the content management system where cross site scripting is not an issue -- you already have full control of the CMS including running arbitrary PHP."

EPSS

Процентиль: 42%
0.00196
Низкий

2.7 Low

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 2.7
nvd
около 7 лет назад

BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error. NOTE: This has been disputed with the following reasoning: "The issue reported requires full developer level access to the content management system where cross site scripting is not an issue -- you already have full control of the CMS including running arbitrary PHP.

EPSS

Процентиль: 42%
0.00196
Низкий

2.7 Low

CVSS3

Дефекты

CWE-639