Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12276

Опубликовано: 05 июн. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Критический

Описание

A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:grandnode:grandnode:4.40:*:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.91282
Критический

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40.

EPSS

Процентиль: 100%
0.91282
Критический

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22