Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7ph9-4h47-rqx5

Опубликовано: 10 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-77