Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gq7-5m56-j2gf

Опубликовано: 11 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.

Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.

EPSS

Процентиль: 83%
0.01946
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.

EPSS

Процентиль: 83%
0.01946
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434