5.3
CVE-2024-3707
- EPSS 0.46%
- Veröffentlicht 12.04.2024 14:15:09
- Zuletzt bearbeitet 04.11.2025 18:13:35
- CVE-Watchlists
- Unerledigt
Exposure of Information Through Directory Listing vulnerability in OpenGnsys
Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to enumerate all files in the web tree by accessing a php file.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.363 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve-coordination@incibe.es | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-548 Exposure of Information Through Directory Listing
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
https://opengnsys.es/web/parche-de-seguridad-cve-2024-370x
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-opengnsys