ZeroHour

CVE-2023-31847

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p48
Published
()
Modified
Description

In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source to read arbitrary files on the client side.

Vendors
davinci project
Products
davinci
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.