Описание
Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allows remote authenticated users to overwrite or read files via crafted requests. Version 5.0.1050 contains the fix.
Ссылки
- ExploitTechnical DescriptionThird Party Advisory
- ExploitTechnical DescriptionThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.0.1000 (включая) до 5.0.1048 (включая)
cpe:2.3:a:biscom:secure_file_transfer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.00216
Низкий
8.1 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allows remote authenticated users to overwrite or read files via crafted requests. Version 5.0.1050 contains the fix.
EPSS
Процентиль: 44%
0.00216
Низкий
8.1 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20