Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68g4-f9x4-95f2

Опубликовано: 03 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.

Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.

EPSS

Процентиль: 52%
0.00293
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.

EPSS

Процентиль: 52%
0.00293
Низкий

8.8 High

CVSS3

Дефекты

CWE-434