Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhcg-rw5x-vg94

Опубликовано: 08 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended directory on the targeted system.

Successful exploitation of this vulnerability could allow an attacker to read arbitrary sensitive files on the targeted system.

This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended directory on the targeted system.

Successful exploitation of this vulnerability could allow an attacker to read arbitrary sensitive files on the targeted system.

EPSS

Процентиль: 37%
0.00455
Низкий

8.7 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

nvd
около 2 месяцев назад

This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended directory on the targeted system. Successful exploitation of this vulnerability could allow an attacker to read arbitrary sensitive files on the targeted system.

EPSS

Процентиль: 37%
0.00455
Низкий

8.7 High

CVSS4

Дефекты

CWE-22