Описание
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.19.0617 (включая)
Одновременно
cpe:2.3:a:changingtec:servisign:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.00411
Низкий
8.3 High
CVSS3
7.5 High
CVSS3
8.5 High
CVSS2
Дефекты
CWE-552
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
EPSS
Процентиль: 61%
0.00411
Низкий
8.3 High
CVSS3
7.5 High
CVSS3
8.5 High
CVSS2
Дефекты
CWE-552