Описание
Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:multisuns:easylog_web\+_firmware:1.13.2.8:*:*:*:*:*:*:*
cpe:2.3:h:multisuns:easylog_web\+:-:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00165
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
около 2 лет назад
Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
EPSS
Процентиль: 38%
0.00165
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
CWE-22