Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rcwq-vxfc-36p5

Опубликовано: 28 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level than intended.

A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level than intended.

EPSS

Процентиль: 68%
0.00575
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level than intended.

EPSS

Процентиль: 68%
0.00575
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22