Описание
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.
Ссылки
- Technical DescriptionThird Party AdvisoryURL Repurposed
- Third Party Advisory
- Technical DescriptionThird Party AdvisoryURL Repurposed
- Third Party Advisory
Уязвимые конфигурации
Одновременно
EPSS
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
Связанные уязвимости
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.
EPSS
6.5 Medium
CVSS3
4 Medium
CVSS2