Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7v2x-vj66-5pgm

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.

EPSS

Процентиль: 30%
0.00112
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 месяцев назад

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.

EPSS

Процентиль: 30%
0.00112
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-434