Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84w3-v2m2-fj4m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead to arbitrary code execution.

Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead to arbitrary code execution.

EPSS

Процентиль: 84%
0.02211
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.2
nvd
почти 5 лет назад

Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead to arbitrary code execution.

EPSS

Процентиль: 84%
0.02211
Низкий

Дефекты

CWE-20