Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47531

Опубликовано: 30 сент. 2024
Источник: nvd
CVSS3: 4.6
CVSS3: 3.5
EPSS Низкий

Описание

Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the compromise of users' devices or data. This vulnerability is fixed in 4.89.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:clinical-genomics:scout:*:*:*:*:*:*:*:*
Версия до 4.89 (исключая)

EPSS

Процентиль: 12%
0.00041
Низкий

4.6 Medium

CVSS3

3.5 Low

CVSS3

Дефекты

CWE-116

EPSS

Процентиль: 12%
0.00041
Низкий

4.6 Medium

CVSS3

3.5 Low

CVSS3

Дефекты

CWE-116