9.8
CVE-2022-4851
- EPSS 0.77%
- Veröffentlicht 29.12.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:36:04
- Quelle security@huntr.dev
- CVE-Watchlists
- Unerledigt
Improper Handling of Values in usememos/memos
Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.77% | 0.508 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| security@huntr.dev | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-229 Improper Handling of Values
The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53
https://huntr.dev/bounties/e3cebc1a-1326-4a08-abad-0414a717fa0f