A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown…
VulDB·CWE-24·Published 2023-12-17
Eine kritische Schwachstelle wurde in rmountjoy92 DashMachine 0.5-4 entdeckt. Betroffen davon ist ein unbekannter Prozess der Datei /settings/delete_file. Durch Beeinflussen des Arguments file mit unbekannten Daten kann eine path traversal: '../filedir'-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung.
A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-248258 is the identifier assigned to this vulnerability.
A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-248258 is the identifier assigned to this vulnerability.
Una vulnerabilidad fue encontrada en rmountjoy92 DashMachine 0.5-4 y clasificada como crítica. Una función desconocida del archivo /settings/delete_file es afectada por este problema. La manipulación del archivo de argumentos conduce a path traversal: '../filedir'. El exploit ha sido divulgado al público y puede utilizarse. VDB-248258 es el identificador asignado a esta vulnerabilidad.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | cve.org | 4.1 | — | — | AV:A/AC:L/Au:S/C:N/I:P/A:P |
| 2.0 | Primary | cve.org | 4.1 | — | — | AV:A/AC:L/Au:S/C:N/I:P/A:P |
| 2.0 | Secondary | NVD | 4.1 | 5.1 | 4.9 | AV:A/AC:L/Au:S/C:N/I:P/A:P |
| 3.0 | Primary | cve.org | 4.6 | — | — | CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| 3.0 | Primary | cve.org | 4.6 | — | — | CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | Primary | NVD | 9.1 | 3.9 | 5.2 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| 3.1 | Primary | cve.org | 4.6 | — | — | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | Primary | cve.org | 4.6 | — | — | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | Secondary | NVD | 4.6 | 2.1 | 2.5 | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |