Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c2h-v384-qmpw

Опубликовано: 03 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

RESERVED There is an arbitrary file upload vulnerability in b2evolution v7.2.5. Attackers can use this vulnerability to execute remote commands.

RESERVED There is an arbitrary file upload vulnerability in b2evolution v7.2.5. Attackers can use this vulnerability to execute remote commands.

EPSS

Процентиль: 75%
0.0091
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 3 лет назад

In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."

EPSS

Процентиль: 75%
0.0091
Низкий

7.2 High

CVSS3

Дефекты

CWE-434