The vulnerability allows an... CVE-2023-48249

- AV AC AU C I A
发布: 2024-01-10
修订: 2024-01-16

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users.

0%
暂无可用Exp或PoC
当前有21条受影响产品信息