6.5
CVE-2023-31847
- EPSS 0.63%
- Veröffentlicht 17.05.2023 01:15:10
- Zuletzt bearbeitet 22.01.2025 17:15:11
- Erkennungen
In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source to read arbitrary files on the client side.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Davinci Project ≫ Davinci Version 0.3.0 Update rc
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.453 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
https://github.com/edp963/davinci/issues/2326