Описание
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
Ссылки
- PatchThird Party Advisory
- Release NotesVendor Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Release NotesVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.2 (исключая)
cpe:2.3:a:hubzilla:hubzilla:*:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00503
Низкий
6.1 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-601
Связанные уязвимости
CVSS3: 6.1
github
почти 4 года назад
An open redirect vulnerability in Hubzilla before version 7.2 allows remote attackers to redirect a logged in user to an arbitrary URL via the rpath parameter.
EPSS
Процентиль: 66%
0.00503
Низкий
6.1 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-601