Описание
Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.
Уязвимые конфигурации
Конфигурация 1Версия до 8.0.2.301 (исключая)
cpe:2.3:a:huawei:ireader:*:*:*:*:*:*:*:*
EPSS
Процентиль: 35%
0.00147
Низкий
7.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.1
github
больше 3 лет назад
Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.
EPSS
Процентиль: 35%
0.00147
Низкий
7.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-22