Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c5r4-m7mf-vx33

Опубликовано: 12 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent.

LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent.

EPSS

Процентиль: 97%
0.36851
Средний

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent.

EPSS

Процентиль: 97%
0.36851
Средний

8.8 High

CVSS3

Дефекты

CWE-434