Описание
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sun.net:ehrd_ctms:-:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.00048
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-23
Связанные уязвимости
CVSS3: 4.9
github
5 месяцев назад
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.
EPSS
Процентиль: 15%
0.00048
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-23