Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-4463

Опубликовано: 12 нояб. 2025
Источник: nvd
EPSS Низкий

Описание

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

EPSS

Процентиль: 72%
0.01452
Низкий

Дефекты

CWE-22

Связанные уязвимости

github
10 месяцев назад

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

EPSS

Процентиль: 72%
0.01452
Низкий

Дефекты

CWE-22