Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-47619

Опубликовано: 13 дек. 2023
Источник: nvd
CVSS3: 8.1
CVSS3: 6.5
EPSS Низкий

Описание

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files and send a GET request to arbitrary URLs and read the response. This issue may lead to Information Disclosure. As of time of publication, no patches are available.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:audiobookshelf:audiobookshelf:*:*:*:*:*:*:*:*
Версия до 2.4.3 (включая)

EPSS

Процентиль: 32%
0.00123
Низкий

8.1 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-918

EPSS

Процентиль: 32%
0.00123
Низкий

8.1 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-918