Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46c3-gjp8-q49w

Опубликовано: 08 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

EPSS

Процентиль: 80%
0.01451
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.9
nvd
около 2 лет назад

Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

EPSS

Процентиль: 80%
0.01451
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-434