Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48xv-cpgv-hr4q

Опубликовано: 12 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.

Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.

EPSS

Процентиль: 18%
0.00056
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.

EPSS

Процентиль: 18%
0.00056
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434