Описание
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.0.5 (исключая)
cpe:2.3:a:welltend:bpmflowwebkit:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00103
Низкий
7.5 High
CVSS3
Дефекты
CWE-36
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
около 1 месяца назад
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
EPSS
Процентиль: 29%
0.00103
Низкий
7.5 High
CVSS3
Дефекты
CWE-36
CWE-22