Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6r8p-cw9m-43r8

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML.

The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML.

EPSS

Процентиль: 60%
0.00402
Низкий

Связанные уязвимости

nvd
около 20 лет назад

The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML.

EPSS

Процентиль: 60%
0.00402
Низкий