Описание
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до IFTOP_P3_2_1_197 (исключая)
cpe:2.3:a:wellchoose:organization_portal_system:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00103
Низкий
7.5 High
CVSS3
Дефекты
CWE-36
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
6 месяцев назад
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
EPSS
Процентиль: 29%
0.00103
Низкий
7.5 High
CVSS3
Дефекты
CWE-36
CWE-22