Vulnerabilidades en Chitora soft
5 resultadosAnálisis Vexday
Chitora soft apresenta 5 vulnerabilidades registradas, com apenas 1 publicada nos últimos 90 dias, indicando risco moderado e estável. Nenhuma das falhas está sob exploração ativa (KEV) e não há críticas de CVSS, reduzindo a pressão imediata. A fraqueza dominante é traversal de diretório (CWE-22), típica de validação inadequada de caminhos de arquivo, que demanda atenção em ambiente de produção mas sem urgência crítica.
CVE-2017-2248—Untrusted search path vulnerability in Installer of Lhaz+ version 3.4.0 and earlier allows an attacker to gain privileges via a Trojan horseEPSS 1.1%CVE-2017-2247—Untrusted search path vulnerability in Self-extracting archive files created by Lhaz version 2.4.0 and earlier allows an attacker to gain prEPSS 1.1%CVE-2017-2249—Untrusted search path vulnerability in Self-extracting archive files created by Lhaz+ version 3.4.0 and earlier allows an attacker to gain pEPSS 1.1%CVE-2017-2246—Untrusted search path vulnerability in Installer of Lhaz version 2.4.0 and earlier allows an attacker to gain privileges via a Trojan horse EPSS 1.1%CVE-2026-41530MEDIUMThe automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected EPSS 0.1%