Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-97x4-c736-8m6j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".

Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".

EPSS

Процентиль: 93%
0.10612
Средний

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".

EPSS

Процентиль: 93%
0.10612
Средний

Дефекты

CWE-434