8.2
CVE-2024-26566
- EPSS 0.5%
- Veröffentlicht 07.03.2024 01:15:52
- Zuletzt bearbeitet 09.07.2026 01:18:55
- CVE-Watchlists
- Unerledigt
An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iscute ≫ Cute Http File Server Version3.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.39 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
|
CWE-288 Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
https://github.com/GZLDL/CVE/blob/main/CVE-2024-26566/CVE-2024-26566%20English.md
https://github.com/GZLDL/CVE/tree/main/Cute%20Http%20File%20Server%20JWT