Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3wvq-9p67-m439

Опубликовано: 07 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.

Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.

EPSS

Процентиль: 50%
0.00268
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.

EPSS

Процентиль: 50%
0.00268
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434