Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-41951

Опубликовано: 27 нояб. 2023
Источник: nvd
CVSS3: 8.5
CVSS3: 9.8
EPSS Низкий

Описание

OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Traversal is possible in Oro\Bundle\GaufretteBundle\FileManager::getTemporaryFileName. With this method, an attacker can pass the path to a non-existent file, which will allow writing the content to a new file that will be available during script execution. This vulnerability has been fixed in version 5.0.9.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:oroinc:oroplatform:*:*:*:*:*:*:*:*
Версия до 5.0.9 (исключая)

EPSS

Процентиль: 61%
0.00414
Низкий

8.5 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.5
github
около 2 лет назад

OroPlatform vulnerable to path traversal during temporary file manipulations

EPSS

Процентиль: 61%
0.00414
Низкий

8.5 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-22