Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mx5-wvh2-fvmf

Опубликовано: 03 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.

The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.

EPSS

Процентиль: 29%
0.00107
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.

EPSS

Процентиль: 29%
0.00107
Низкий

8.8 High

CVSS3

Дефекты

CWE-434