Описание
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."
Ссылки
- Release NotesVendor Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- Release NotesVendor Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 0.35.2 (включая)
cpe:2.3:a:fomori:cherrymusic:*:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06564
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 91%
0.06564
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22