Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rrqx-xr4w-7wpj

Опубликовано: 07 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the intended directory.

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the intended directory.

EPSS

Процентиль: 92%
0.08199
Низкий

7.3 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 года назад

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the intended directory.

EPSS

Процентиль: 92%
0.08199
Низкий

7.3 High

CVSS3

Дефекты

CWE-22