Описание
SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations.
EPSS
Процентиль: 24%
0.00319
Низкий
Дефекты
CWE-22
Связанные уязвимости
github
около 1 месяца назад
SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations.
EPSS
Процентиль: 24%
0.00319
Низкий
Дефекты
CWE-22