Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9ff2-h59x-3rvx

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 8.8

Описание

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

EPSS

Процентиль: 15%
0.00047
Низкий

4.8 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
22 дня назад

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

EPSS

Процентиль: 15%
0.00047
Низкий

4.8 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434