Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-chw4-gjvw-3gxc

Опубликовано: 08 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.3

Описание

Melis Platform CMS Unauthenticated File Upload Leading to RCE

File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter.

Пакеты

Наименование

melisplatform/melis-cms-slider

composer
Затронутые версииВерсия исправления

< 5.3.1

5.3.1

EPSS

Процентиль: 37%
0.00154
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-43

Связанные уязвимости

nvd
4 месяца назад

File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter.

EPSS

Процентиль: 37%
0.00154
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-43