Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-87vx-4xf9-32hg

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.

EPSS

Процентиль: 66%
0.0051
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.

CVSS3: 8.8
debian
около 2 месяцев назад

Serendipity 2.4.0 contains a remote code execution vulnerability that ...

EPSS

Процентиль: 66%
0.0051
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434