Описание
A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.
Ссылки
- Product
- Broken LinkNot Applicable
- Third Party AdvisoryUS Government ResourceVDB Entry
- ExploitPatchThird Party Advisory
- Product
- Broken LinkNot Applicable
- Third Party AdvisoryUS Government ResourceVDB Entry
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:afterlogic:aurora_files:9.7.3:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00225
Низкий
8.8 High
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 8.8
github
больше 2 лет назад
A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.
EPSS
Процентиль: 45%
0.00225
Низкий
8.8 High
CVSS3
Дефекты
CWE-502