Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c6jj-hc2x-m9jc

Опубликовано: 07 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered.

Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered.

EPSS

Процентиль: 87%
0.03357
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered.

EPSS

Процентиль: 87%
0.03357
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306