ZeroHour

CVE-2022-23766

CVSS 3.1
8.8 high
EPSS
<1%p43
Published
()
Modified
Description

An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a general website.

Vendors
bigfile
Products
bigfileagent
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.