Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6m2-cj32-wg84

Опубликовано: 09 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.

The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.

EPSS

Процентиль: 20%
0.00063
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.

EPSS

Процентиль: 20%
0.00063
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918