VulnerabilityAnalyzed
CVE-2024-3707
Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto).
MEDIUM 5.3EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to enumerate all files in the web tree by accessing a php file.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-548
- Affected
- opengnsys/opengnsys
- Source
- cve-coordination@incibe.es
References
- https://opengnsys.es/web/parche-de-seguridad-cve-2024-370xVendor Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-opengnsysThird Party Advisory
- https://opengnsys.es/web/parche-de-seguridad-cve-2024-370xVendor Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-opengnsysThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.