Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rfr-j4c8-vw6c

Опубликовано: 30 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may be affected by some known vulnerabilities.

Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may be affected by some known vulnerabilities.

EPSS

Процентиль: 36%
0.0015
Низкий

7.2 High

CVSS3

Дефекты

CWE-349

Связанные уязвимости

CVSS3: 7.2
nvd
больше 1 года назад

Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may be affected by some known vulnerabilities.

EPSS

Процентиль: 36%
0.0015
Низкий

7.2 High

CVSS3

Дефекты

CWE-349