Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-264x-w2cv-phgq

Опубликовано: 09 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2
CVSS3: 4.7

Описание

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

EPSS

Процентиль: 15%
0.0005
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.7
nvd
около 2 месяцев назад

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

EPSS

Процентиль: 15%
0.0005
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-284