Описание
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's export_pth function. This issue may lead to reading arbitrary files on the Applio server. It can also be used in conjunction with blind server-side request forgery to read files from servers on the internal network that the Applio server has access to. As of time of publication, no known patches are available.
Ссылки
- Product
- Product
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.2.8-bugfix (включая)
cpe:2.3:a:applio:applio:*:*:*:*:*:*:*:*
EPSS
Процентиль: 40%
0.00186
Низкий
7.5 High
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo
EPSS
Процентиль: 40%
0.00186
Низкий
7.5 High
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo