Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-67q5-5xj6-vp4m

Опубликовано: 04 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the imageProxy.type.php endpoint, external users are capable of accessing files on the server.

A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the imageProxy.type.php endpoint, external users are capable of accessing files on the server.

EPSS

Процентиль: 50%
0.00264
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 8.8
nvd
около 3 лет назад

A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server.

EPSS

Процентиль: 50%
0.00264
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-552