René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

89 lines
2.4 KiB
JSON

{
"id": "CVE-2022-41711",
"sourceIdentifier": "help@fluidattacks.com",
"published": "2022-10-25T21:15:49.150",
"lastModified": "2022-10-28T17:51:09.530",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users."
},
{
"lang": "es",
"value": "Badaso versi\u00f3n 2.6.0, permite a un atacante remoto no autenticado ejecutar c\u00f3digo arbitrario de forma remota en el servidor. Esto es posible porque la aplicaci\u00f3n no comprueba apropiadamente los datos descargados por los usuarios"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:uatech:badaso:2.6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "2F747296-3BE2-4660-95EB-C68E72A79EAF"
}
]
}
]
}
],
"references": [
{
"url": "https://fluidattacks.com/advisories/harlow/",
"source": "help@fluidattacks.com",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
]
},
{
"url": "https://github.com/uasoft-indonesia/badaso/issues/802",
"source": "help@fluidattacks.com",
"tags": [
"Issue Tracking",
"Third Party Advisory"
]
}
]
}