Описание
Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This vulnerability is exploited via an error caused by including non-existent path environment variables.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.19 (включая)Версия до 1.1.2 (включая)Версия до 1.1.2 (включая)
Одно из
cpe:2.3:a:kumilabs:swift_file_transfer:*:*:*:*:*:blackberry:*:*
cpe:2.3:a:kumilabs:swift_file_transfer:*:*:*:*:*:android:*:*
cpe:2.3:a:kumilabs:swift_file_transfer:*:*:*:*:*:iphone_os:*:*
EPSS
Процентиль: 64%
0.00462
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
больше 3 лет назад
Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This vulnerability is exploited via an error caused by including non-existent path environment variables.
EPSS
Процентиль: 64%
0.00462
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22