Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6wwx-2f48-jxh8

Опубликовано: 26 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files that compromise the system. In addition, it is vulnerable to Path Traversal, which allows files to be written to arbitrary directories within the web root.

Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files that compromise the system. In addition, it is vulnerable to Path Traversal, which allows files to be written to arbitrary directories within the web root.

EPSS

Процентиль: 23%
0.00075
Низкий

8.6 High

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
5 месяцев назад

Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files that compromise the system. In addition, it is vulnerable to Path Traversal, which allows files to be written to arbitrary directories within the web root.

EPSS

Процентиль: 23%
0.00075
Низкий

8.6 High

CVSS4

Дефекты

CWE-434