Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-39299

Опубликовано: 03 нояб. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network.

We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:*
Версия от 4.8.0 (включая) до 4.8.11 (исключая)
cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:*
Версия от 5.1.0 (включая) до 5.1.16 (исключая)
cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:*
Версия от 5.3.0 (включая) до 5.3.23 (исключая)

EPSS

Процентиль: 40%
0.00177
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

EPSS

Процентиль: 40%
0.00177
Низкий

7.5 High

CVSS3

Дефекты

CWE-22