CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It may be remotely exploitable.
CVE
CVE-2023-48249
Severity
MEDIUM
CVSS
6.5
EPSS
0.78%
Original NVD Description
The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users.
Related CVEs
Other vulnerabilities affecting the same vendor(s)