Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vg3q-rcxr-8qqv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Successful exploitation requires valid credentials to an account with "Edit" access to "System Customization".

Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Successful exploitation requires valid credentials to an account with "Edit" access to "System Customization".

EPSS

Процентиль: 17%
0.00055
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 4.7
nvd
больше 7 лет назад

Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Successful exploitation requires valid credentials to an account with "Edit" access to "System Customization".

EPSS

Процентиль: 17%
0.00055
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-732