Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5v3q-4g69-424q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.

ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.

EPSS

Процентиль: 51%
0.00282
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.

EPSS

Процентиль: 51%
0.00282
Низкий