CVE-2026-30286
קריטית 9.8
תיאור (מקור, אנגלית)
An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-27/7/2026
- CWE
- CWE-22
מוצרים מושפעים
funambol: zefiro
קישורים
- https://github.com/Secsys-FDU/AF_CVEs/issues/14 Third Party Advisory
- https://play.google.com/store/apps/details?id=com.funambol.zefiro Product
- https://secsys.fudan.edu.cn/ Not Applicable
- https://zefiro.me/ Product