Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6pj9-476v-v64v

Опубликовано: 20 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.

Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.

EPSS

Процентиль: 78%
0.01174
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.

EPSS

Процентиль: 78%
0.01174
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434