Описание
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read arbitrary files outside the intended directory.
EPSS
Процентиль: 44%
0.00554
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-35
Связанные уязвимости
CVSS3: 9.8
github
4 месяца назад
A path traversal condition in Intrado 911 Emergency Gateway could allow an attacker with existing network access the ability to access the EGW management interface without authentication. Successful exploitation of this vulnerability could allow a user to read, modify, or delete files.
EPSS
Процентиль: 44%
0.00554
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-35