Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3w76-xwmv-869f

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.

NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.

EPSS

Процентиль: 97%
0.41857
Средний

9.8 Critical

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.

EPSS

Процентиль: 97%
0.41857
Средний

9.8 Critical

CVSS3

Дефекты

CWE-330