Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3fvv-4h43-9g7x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.

The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.

EPSS

Процентиль: 85%
0.02631
Низкий

Связанные уязвимости

CVSS3: 7.2
nvd
больше 5 лет назад

The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.

EPSS

Процентиль: 85%
0.02631
Низкий