CVE-2021-44315 Information
Jun 07, 2022
cve
Description
In Bus Pass Management System v1.0 Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application for example: Any file which contains sensitive information of the user or server.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/abhiunix/Bus-Pass-Management-System-v1.0/blob/master/Directory%20listing/Report_Directory%20listing.pdf https://github.com/abhiunix/Bus-Pass-Management-System-v1.0/tree/master/Directory%20listing
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: