Syspass
cpe:2.3:a:syspass:syspass:*:*:*:*:*:*:*
- ~3.2
A vulnerability exists in Syspass versions 3.2.x within the account file upload feature, where special characters in filenames are not properly managed. This oversight allows for the unintentional disclosure of the web application's source code, revealing sensitive information such as the database password.
Exploitation of this vulnerability results in the unauthorized disclosure of the web application's source code, including sensitive information like the database password.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.