Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gm7-8wqr-q8wm

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.

NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.

EPSS

Процентиль: 39%
0.00176
Низкий

7.2 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 2
nvd
почти 8 лет назад

NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.

EPSS

Процентиль: 39%
0.00176
Низкий

7.2 High

CVSS3

Дефекты

CWE-20