Логотип exploitDog
bind:CVE-2025-42970
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-42970

Количество 3

Количество 3

nvd логотип

CVE-2025-42970

7 месяцев назад

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directory and overwriting files in arbitrary locations. This vulnerability has a high impact on the integrity and availability of the application with no impact on confidentiality.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3ccj-82gj-65cg

7 месяцев назад

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directory and overwriting files in arbitrary locations. This vulnerability has a high impact on the integrity and availability of the application with no impact on confidentiality.

CVSS3: 5.8
EPSS: Низкий
fstec логотип

BDU:2025-16217

7 месяцев назад

Уязвимость утилиты сжатия и распаковки файлов SAPCAR, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записывать произвольные файлы

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-42970

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directory and overwriting files in arbitrary locations. This vulnerability has a high impact on the integrity and availability of the application with no impact on confidentiality.

CVSS3: 5.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3ccj-82gj-65cg

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directory and overwriting files in arbitrary locations. This vulnerability has a high impact on the integrity and availability of the application with no impact on confidentiality.

CVSS3: 5.8
0%
Низкий
7 месяцев назад
fstec логотип
BDU:2025-16217

Уязвимость утилиты сжатия и распаковки файлов SAPCAR, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записывать произвольные файлы

CVSS3: 5.8
0%
Низкий
7 месяцев назад

Уязвимостей на страницу