Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6f3w-c86g-f4j3

Опубликовано: 27 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operation or disrupt service.

SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operation or disrupt service.

EPSS

Процентиль: 62%
0.0043
Низкий

8.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operation or disrupt service.

EPSS

Процентиль: 62%
0.0043
Низкий

8.8 High

CVSS3

Дефекты

CWE-22