CVE-2023-39141 is a high-severity path traversal vulnerability affecting webui-aria2 commit 4fe2e, allowing unauthenticated attackers to access sensitive information. With a CVSS score of 7.5, the vulnerability is easily exploitable over the network with no user interaction, potentially leading to full confidentiality compromise. While not currently on the KEV catalog or Hot List, and with no reported active exploitation or Metasploit modules, a Nuclei template exists, and its high EPSS score indicates a significant likelihood of future exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ziahamza:webui-aria2:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.