Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-83jr-29h8-jh58

Опубликовано: 20 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

EPSS

Процентиль: 65%
0.00492
Низкий

7.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.8
nvd
почти 4 года назад

Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

EPSS

Процентиль: 65%
0.00492
Низкий

7.8 High

CVSS3

Дефекты

CWE-434