Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8xh2-xr8x-3g8x

Опубликовано: 18 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability allows an attacker to upload a dangerous file type by sending a POST request using the parameter “cctl00$ContentPlaceHolder1$fuAdjunto” in “/MemberPages/ntf_absentismo.aspx”.

Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability allows an attacker to upload a dangerous file type by sending a POST request using the parameter “cctl00$ContentPlaceHolder1$fuAdjunto” in “/MemberPages/ntf_absentismo.aspx”.

EPSS

Процентиль: 24%
0.00081
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
5 месяцев назад

Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability allows an attacker to upload a dangerous file type by sending a POST request using the parameter “cctl00$ContentPlaceHolder1$fuAdjunto” in “/MemberPages/ntf_absentismo.aspx”.

EPSS

Процентиль: 24%
0.00081
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-434