Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7365-g5qg-hxx6

Опубликовано: 13 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.

Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.

EPSS

Процентиль: 55%
0.0033
Низкий

8.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
nvd
около 3 лет назад

Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.

EPSS

Процентиль: 55%
0.0033
Низкий

8.8 High

CVSS3

Дефекты

CWE-22