Vulnerabilities
Vulnerable Software
Zucchetti:  Security Vulnerabilities
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-10-30
Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restricted location (dot-dot-slash notation) to access files or directories that are elsewhere on the system. Through this vulnerability it is possible to read the application's java sources from /WEB-INF/classes/*.class
CVSS Score
7.5
EPSS Score
0.026
Published
2019-06-19


Contact Us

Shodan ® - All rights reserved