Описание
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.0.1 (исключая)
cpe:2.3:a:cksource:ckfinder:*:*:*:*:*:asp.net:*:*
EPSS
Процентиль: 16%
0.00049
Низкий
5 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-23
CWE-22
Связанные уязвимости
CVSS3: 5
debian
2 месяца назад
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users c ...
CVSS3: 5
github
2 месяца назад
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.
EPSS
Процентиль: 16%
0.00049
Низкий
5 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-23
CWE-22