Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4h8j-fjxw-9pcc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.

A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.

EPSS

Процентиль: 80%
0.0145
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.

CVSS3: 8.8
fstec
около 5 лет назад

Уязвимость сервера отчетов WebReports, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю загрузить вредоносные файлы и выполнить произвольный код

EPSS

Процентиль: 80%
0.0145
Низкий

Дефекты

CWE-434