7.5

CVE-2022-44343

CRMEB 4.4.4 is vulnerable to Any File download.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CrmebCrmeb Version4.4.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.46
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://github.com/crmeb/CRMEB
Vendor Advisory
https://gist.github.com/Nmslgkd/442d8055914887d7c99c4e70a63da4c2
Third Party Advisory