Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-573j-p665-w834

Опубликовано: 17 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.9

Описание

A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a malicious file.

A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a malicious file.

EPSS

Процентиль: 52%
0.00286
Низкий

9.9 Critical

CVSS4

Дефекты

CWE-98

Связанные уязвимости

nvd
10 месяцев назад

A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a malicious file.

EPSS

Процентиль: 52%
0.00286
Низкий

9.9 Critical

CVSS4

Дефекты

CWE-98