Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hj2-qp52-8qvm

Опубликовано: 30 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

EPSS

Процентиль: 97%
0.32365
Средний

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

EPSS

Процентиль: 97%
0.32365
Средний

9.8 Critical

CVSS3

Дефекты

CWE-434