6.5
CVE-2021-44534
- EPSS 0.23%
- Veröffentlicht 31.05.2024 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:31:11
- Quelle support@hackerone.com
- CVE-Watchlists
- Unerledigt
Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerexpressionengine
≫
Produkt
expressionengine
Default Statusunknown
Version
6.0.3
Status
affected
Herstellerexpressionengine
≫
Produkt
expressionengine
Default Statusunknown
Version
6.0.0
Status
unaffected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.455 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.