Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-534f-4cxm-43gw

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.8

Описание

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.

EPSS

Процентиль: 51%
0.0028
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434
CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
25 дней назад

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.

EPSS

Процентиль: 51%
0.0028
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434
CWE-94