Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-23366

Опубликовано: 06 окт. 2023
Источник: nvd
CVSS3: 7.7
CVSS3: 6.5
EPSS Низкий

Описание

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network.

We have already fixed the vulnerability in the following version: Music Station 5.3.22 and later

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:*
Версия от 5.3.0 (включая) до 5.3.22 (исключая)

EPSS

Процентиль: 35%
0.00147
Низкий

7.7 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 7.7
github
больше 2 лет назад

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: Music Station 5.3.22 and later

EPSS

Процентиль: 35%
0.00147
Низкий

7.7 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-22
CWE-22