Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c37c-p2gq-c2g7

Опубликовано: 05 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStudent of the file src/main/Java/com/wdd/studentmanager/controller/StudentController. java. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStudent of the file src/main/Java/com/wdd/studentmanager/controller/StudentController. java. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 40%
0.00183
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.3
nvd
около 1 года назад

A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStudent of the file src/main/Java/com/wdd/studentmanager/controller/StudentController. java. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 40%
0.00183
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-284