Описание
A vulnerability classified as critical has been found in anji-plus AJ-Report up to 1.4.1. This affects the function decompress of the component ZIP File Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266265 was assigned to this vulnerability.
Ссылки
- Exploit
- Broken Link
- Permissions RequiredVDB Entry
- Permissions RequiredVDB Entry
- Exploit
- Broken Link
- Permissions RequiredVDB Entry
- Permissions RequiredVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.1 (включая)
cpe:2.3:a:anji-plus:aj-report:*:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00174
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-22
EPSS
Процентиль: 39%
0.00174
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-22