Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrxq-687c-64w5

Опубликовано: 25 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In WhatsUp Gold versions released before 2023.1.3, 

an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.

In WhatsUp Gold versions released before 2023.1.3, 

an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.

EPSS

Процентиль: 45%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

In WhatsUp Gold versions released before 2023.1.3,  an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.

EPSS

Процентиль: 45%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22