Vulnerability Description
EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send GET requests to the files directory to download database files like db.sq3 containing application data and credentials.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/45868
- https://www.vulncheck.com/advisories/eversync-arbitrary-file-download-via-files-
FAQ
What is CVE-2018-25164?
CVE-2018-25164 is a vulnerability with a CVSS score of 7.5 (HIGH). EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send ...
How severe is CVE-2018-25164?
CVE-2018-25164 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25164?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.