Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37f5-2pjr-46xw

Опубликовано: 24 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.9
CVSS3: 8.1

Описание

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

EPSS

Процентиль: 35%
0.00144
Низкий

8.9 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-434
CWE-77

Связанные уязвимости

CVSS3: 8.1
nvd
больше 1 года назад

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

EPSS

Процентиль: 35%
0.00144
Низкий

8.9 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-434
CWE-77