Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-4402

Опубликовано: 11 дек. 2022
Источник: nvd
CVSS3: 4.7
CVSS3: 7.2
EPSS Низкий

Описание

A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215271.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:docsys_project:docsys:*:*:*:*:*:*:*:*
Версия до 2.02.37 (включая)

EPSS

Процентиль: 73%
0.00756
Низкий

4.7 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 7.2
github
около 3 лет назад

A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215271.

EPSS

Процентиль: 73%
0.00756
Низкий

4.7 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-22
CWE-22