Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w5p-qwh4-xc23

Опубликовано: 23 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting vulnerability classes.

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting vulnerability classes.

EPSS

Процентиль: 55%
0.00328
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22
CWE-23

Связанные уязвимости

CVSS3: 6.5
nvd
12 месяцев назад

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting vulnerability classes.

EPSS

Процентиль: 55%
0.00328
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22
CWE-23