Логотип exploitDog
bind:CVE-2019-25574
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-25574

Количество 1

Количество 1

github логотип

GHSA-23hm-6gvp-w3w5

5 дней назад

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23hm-6gvp-w3w5

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

CVSS3: 6.5
5 дней назад

Уязвимостей на страницу