Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-10024

Опубликовано: 07 янв. 2023
Источник: nvd
CVSS3: 5.5
CVSS3: 9.8
CVSS2: 5.2
EPSS Низкий

Описание

A vulnerability classified as critical was found in hoffie larasync. This vulnerability affects unknown code of the file repository/content/file_storage.go. The manipulation leads to path traversal. The name of the patch is 776bad422f4bd4930d09491711246bbeb1be9ba5. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217612.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:larasync_project:larasync:*:*:*:*:*:*:*:*
Версия до 2015-01-20 (исключая)

EPSS

Процентиль: 68%
0.00572
Низкий

5.5 Medium

CVSS3

9.8 Critical

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
github
около 3 лет назад

A vulnerability classified as critical was found in hoffie larasync. This vulnerability affects unknown code of the file repository/content/file_storage.go. The manipulation leads to path traversal. The name of the patch is 776bad422f4bd4930d09491711246bbeb1be9ba5. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217612.

EPSS

Процентиль: 68%
0.00572
Низкий

5.5 Medium

CVSS3

9.8 Critical

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-22