Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23766

Опубликовано: 19 сент. 2022
Источник: nvd
CVSS3: 7.8
CVSS3: 8.8
EPSS Низкий

Описание

An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a general website.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:bigfile:bigfileagent:*:*:*:*:*:*:*:*
Версия до 1.0.1.9 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 57%
0.00345
Низкий

7.8 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a general website.

EPSS

Процентиль: 57%
0.00345
Низкий

7.8 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-20
CWE-20