Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vv78-mf5r-v5q7

Опубликовано: 05 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. The configuration backup file, which contains username hashes, cleartext passwords, and API keys, can be downloaded. This could allow a malicious actor to crack the passwords offline and/or utilize the API keys to control the remote application.

Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. The configuration backup file, which contains username hashes, cleartext passwords, and API keys, can be downloaded. This could allow a malicious actor to crack the passwords offline and/or utilize the API keys to control the remote application.

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumerates Contact information on the host which contains usernames, e-mail addresses, and other internal information stored within the web app.

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22