Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rg3-f299-p33w

Опубликовано: 13 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 1.6

Описание

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

EPSS

Процентиль: 49%
0.00259
Низкий

1.6 Low

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 1.6
nvd
около 1 года назад

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

EPSS

Процентиль: 49%
0.00259
Низкий

1.6 Low

CVSS3

Дефекты

CWE-434