ZeroHour

CVE-2023-4172

PoC
CVSS 3.1
7.5 high
EPSS
<1%p58
Published
()
Modified
Description

A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236207.

Vendors
cdwanjiang
Products
flash flood disaster monitoring and warning system
Weakness
CWE-36, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.