Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52vj-66ff-3q3r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.

EPSS

Процентиль: 32%
0.00123
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8
nvd
почти 5 лет назад

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.

EPSS

Процентиль: 32%
0.00123
Низкий

Дефекты

CWE-434