Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9p44-q66p-xm6p

Опубликовано: 21 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.7

Описание

ProcessWire CMS vulnerable to resource-exhaustion Denial of Service

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.

Пакеты

Наименование

processwire/processwire

composer
Затронутые версииВерсия исправления

<= 3.0.246

Отсутствует

EPSS

Процентиль: 18%
0.00058
Низкий

5.7 Medium

CVSS4

Дефекты

CWE-400
CWE-409

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.

EPSS

Процентиль: 18%
0.00058
Низкий

5.7 Medium

CVSS4

Дефекты

CWE-400
CWE-409