A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue…
VulDB·CWE-24·Published 2024-01-29
Eine problematische Schwachstelle wurde in Sichuan Yougou Technology KuERP bis 1.0.4 entdeckt. Hierbei geht es um die Funktion del_sn_db der Datei /application/index/controller/Service.php. Mit der Manipulation des Arguments file mit unbekannten Daten kann eine path traversal: '../filedir'-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung.
A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the function del_sn_db of the file /application/index/controller/Service.php. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-252254 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the function del_sn_db of the file /application/index/controller/Service.php. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-252254 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Una vulnerabilidad clasificada como problemática fue encontrada en Sichuan Yougou Technology KuERP hasta 1.0.4. La función del_sn_db del archivo /application/index/controller/Service.php es afectada por esta vulnerabilidad. La manipulación del argumentos file conduce a path traversal: '../filedir'. La explotación ha sido divulgada al público y puede utilizarse. VDB-252254 es el identificador asignado a esta vulnerabilidad. NOTA: Se contactó primeramente con proveedor sobre esta divulgación, pero no respondió de ninguna manera.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | cve.org | 4.8 | — | — | AV:A/AC:L/Au:N/C:N/I:P/A:P |
| 2.0 | Primary | cve.org | 4.8 | — | — | AV:A/AC:L/Au:N/C:N/I:P/A:P |
| 2.0 | Secondary | NVD | 4.8 | 6.5 | 4.9 | AV:A/AC:L/Au:N/C:N/I:P/A:P |
| 3.0 | Primary | cve.org | 5.4 | — | — | CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
| 3.0 | Primary | cve.org | 5.4 | — | — | CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | Primary | NVD | 9.8 | 3.9 | 5.9 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | Primary | cve.org | 5.4 | — | — | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | Primary | cve.org | 5.4 | — | — | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | Secondary | NVD | 5.4 | 2.8 | 2.5 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |