Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41185

Опубликовано: 26 окт. 2021
Источник: nvd
CVSS3: 8.8
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made. Users should upgrade to version 8.12.7. As a workaround, users may manually apply the changes from the fix commit.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mycodo_project:mycodo:*:*:*:*:*:*:*:*
Версия до 8.12.7 (исключая)

EPSS

Процентиль: 64%
0.00464
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-22

EPSS

Процентиль: 64%
0.00464
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-22