Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-28052

Опубликовано: 13 апр. 2022
Источник: nvd
CVSS3: 8
CVSS2: 6
EPSS Низкий

Описание

Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:roothub:roothub:2.6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.02037
Низкий

8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8
github
почти 4 года назад

Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.

EPSS

Процентиль: 83%
0.02037
Низкий

8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-22