Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqjv-qq8w-56qr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.

In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.

EPSS

Процентиль: 46%
0.00236
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-353
CWE-88

Связанные уязвимости

CVSS3: 8.7
nvd
больше 5 лет назад

In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.

EPSS

Процентиль: 46%
0.00236
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-353
CWE-88