Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9737-ffv6-mv28

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

EPSS

Процентиль: 68%
0.00582
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-863
CWE-94

Связанные уязвимости

CVSS3: 9.9
nvd
почти 5 лет назад

NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

EPSS

Процентиль: 68%
0.00582
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-863
CWE-94