Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65x8-9vgm-5fg5

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Feehi CMS arbitrary file upload vulnerability

Feehi CMS 2.1.0-beta is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to potentially upload malicious files.

Пакеты

Наименование

feehi/cms

composer
Затронутые версииВерсия исправления

<= 2.1.0-beta

Отсутствует

EPSS

Процентиль: 84%
0.02064
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 5 лет назад

Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to potentially upload malicious files.

EPSS

Процентиль: 84%
0.02064
Низкий

7.2 High

CVSS3

Дефекты

CWE-434