Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-345h-g8ww-x3jg

Опубликовано: 30 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10

Описание

An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file.

An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file.

EPSS

Процентиль: 41%
0.00194
Низкий

10 Critical

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
9 дней назад

An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file.

EPSS

Процентиль: 41%
0.00194
Низкий

10 Critical

CVSS4

Дефекты

CWE-434