Логотип exploitDog
bind:CVE-2024-46446
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-46446

Количество 2

Количество 2

nvd логотип

CVE-2024-46446

больше 1 года назад

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq72-m3h5-wf3q

больше 1 года назад

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-46446

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq72-m3h5-wf3q

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.

CVSS3: 9.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу