Логотип exploitDog
bind:CVE-2024-0550
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-0550

Количество 2

Количество 2

nvd логотип

CVE-2024-0550

почти 2 года назад

A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissions to the system before executing this attack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6hmr-48fm-wfhx

почти 2 года назад

A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissions to the system before executing this attack.

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-0550

A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissions to the system before executing this attack.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-6hmr-48fm-wfhx

A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissions to the system before executing this attack.

CVSS3: 9.6
1%
Низкий
почти 2 года назад

Уязвимостей на страницу