Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gw3-9jpp-7crr

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

EPSS

Процентиль: 87%
0.03516
Низкий

Связанные уязвимости

nvd
почти 21 год назад

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

EPSS

Процентиль: 87%
0.03516
Низкий