SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-2584

The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the…

MEDIUM 5.0EPSS 1.40%

Does this matter?

Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.

Description

The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the SourceFile property in conjunction with an http URL in the DestURL property.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.40% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
realpage/module activex controls
Source
PSIRT-CNA@flexerasoftware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.