Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4vq-6w73-6rm7

Опубликовано: 04 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint.

Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint.

EPSS

Процентиль: 30%
0.00114
Низкий

7.6 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.6
nvd
почти 2 года назад

Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint.

EPSS

Процентиль: 30%
0.00114
Низкий

7.6 High

CVSS3

Дефекты

CWE-94