CVE-2024-21136: Oracle Retail Xstore Suite – Pre-authenticated Path Traversal

CVE-2024-21136: Oracle Retail Xstore Suite - Pre-authenticated Path Traversal-渗透云记 - 专注于网络安全与技术分享
CVE-2024-21136: Oracle Retail Xstore Suite – Pre-authenticated Path Traversal
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-21136: Oracle Retail Xstore Suite – Pre-authenticated Path Traversal

漏洞描述

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change).

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享