7.5
CVE-2018-8947
- EPSS 16.17%
- Veröffentlicht 25.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:39
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Laravel Log Viewer Project ≫ Laravel Log Viewer Version < 0.13.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 16.17% | 0.945 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.