Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jqp-827w-wpmw

Опубликовано: 15 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.

Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.

EPSS

Процентиль: 60%
0.00395
Низкий

10 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 10
nvd
больше 1 года назад

Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.

EPSS

Процентиль: 60%
0.00395
Низкий

10 Critical

CVSS3

Дефекты

CWE-434