Описание
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
Ссылки
- Exploit
- ExploitThird Party AdvisoryVDB Entry
- Exploit
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:unifiedremote:unified_remote:3.13.0:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00666
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 9.8
github
около 2 лет назад
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
EPSS
Процентиль: 71%
0.00666
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-611