Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xxr-prx9-m533

Опубликовано: 24 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.9
CVSS3: 8.8

Описание

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

EPSS

Процентиль: 52%
0.00755
Низкий

8.9 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434
CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

EPSS

Процентиль: 52%
0.00755
Низкий

8.9 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434
CWE-77