Описание
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with the URL parameter and access arbitrary file on system.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:cellopoint:cellos:4.1.10:build20190922:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00239
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-918
CWE-918
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
Cellopoint Cellos v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with the URL parameter and access arbitrary file on system.
EPSS
Процентиль: 47%
0.00239
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-918
CWE-918