Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-50404

Опубликовано: 06 дек. 2024
Источник: nvd
CVSS3: 8.8
EPSS Средний

Описание

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations.

We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:qnap:qsync_central:*:*:*:*:*:*:*:*
Версия от 4.4.0 (включая) до 4.4.0.16 (исключая)

EPSS

Процентиль: 97%
0.40675
Средний

8.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 8.8
github
около 1 года назад

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later

EPSS

Процентиль: 97%
0.40675
Средний

8.8 High

CVSS3

Дефекты

CWE-59