Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5972-jjp3-vqm8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs without the Maintenance Mode setting.

In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs without the Maintenance Mode setting.

EPSS

Процентиль: 75%
0.00878
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs without the Maintenance Mode setting.

EPSS

Процентиль: 75%
0.00878
Низкий