Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mv9-7wfj-624h

Опубликовано: 31 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 4.3

Описание

Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.

Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.

EPSS

Процентиль: 3%
0.00016
Низкий

5.1 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
8 дней назад

Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.

EPSS

Процентиль: 3%
0.00016
Низкий

5.1 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-352