Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xxr-prx9-m533

Опубликовано: 24 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.9
CVSS3: 8.8

Описание

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

EPSS

Процентиль: 44%
0.00219
Низкий

8.9 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434
CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

EPSS

Процентиль: 44%
0.00219
Низкий

8.9 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434
CWE-77