Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14924

Опубликовано: 10 авг. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but not oldAbsolutePath. By leveraging this vulnerability, an adversary can make an inaccessible file be available (the credential of the app, for instance).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gcdwebserver_project:gcdwebserver:*:*:*:*:*:*:*:*
Версия до 3.5.3 (исключая)

EPSS

Процентиль: 60%
0.00401
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but not oldAbsolutePath. By leveraging this vulnerability, an adversary can make an inaccessible file be available (the credential of the app, for instance).

EPSS

Процентиль: 60%
0.00401
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-863