ZeroHour

CVE-2017-15309

CVSS 3.0
7.1 high
EPSS
<1%p60
Published
()
Modified
Description

Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.

Vendors
huawei
Products
ireader
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.