Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqj4-ph2f-7q79

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.

ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.

EPSS

Процентиль: 73%
0.00751
Низкий

7.5 High

CVSS3

Дефекты

CWE-330
CWE-331

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.

EPSS

Процентиль: 73%
0.00751
Низкий

7.5 High

CVSS3

Дефекты

CWE-330
CWE-331