Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j4g-q4pc-fmcw

Опубликовано: 14 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.

Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.

EPSS

Процентиль: 66%
0.00513
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.

EPSS

Процентиль: 66%
0.00513
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89