Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8h5j-7xvq-97fq

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.

An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.

EPSS

Процентиль: 62%
0.00427
Низкий

7.8 High

CVSS3

Дефекты

CWE-185

Связанные уязвимости

CVSS3: 7.8
nvd
больше 7 лет назад

An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.

EPSS

Процентиль: 62%
0.00427
Низкий

7.8 High

CVSS3

Дефекты

CWE-185