Логотип exploitDog
bind:CVE-2023-25650
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-25650

Количество 2

Количество 2

nvd логотип

CVE-2023-25650

около 2 лет назад

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pg7f-8r86-68j5

около 2 лет назад

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-25650

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-pg7f-8r86-68j5

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу