Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w96m-rw5m-pf44

Опубликовано: 12 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 6.5

Описание

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows File Manipulation. The endpoint requires authentication.This issue affects Envoy: from 4.x to 8.0 and < 8.2.4225.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows File Manipulation. The endpoint requires authentication.This issue affects Envoy: from 4.x to 8.0 and < 8.2.4225.

EPSS

Процентиль: 44%
0.00213
Низкий

9.2 Critical

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows File Manipulation. The endpoint requires authentication.This issue affects Envoy: from 4.x to 8.0 and < 8.2.4225.

EPSS

Процентиль: 44%
0.00213
Низкий

9.2 Critical

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22