Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr7j-rwmv-vgch

Опубликовано: 07 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Duplicate Advisory: aimeos-core arbitrary file upload vulnerability

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-rhc2-23c2-ww7c. This link is maintained to preserve external references.

Original Description

An arbitrary file upload vulnerability in the image upload function of aimeos-core v2024.04 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Пакеты

Наименование

aimeos/aimeos-core

composer
Затронутые версииВерсия исправления

< 2024.04.5

2024.04.5

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

nvd
больше 1 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-37295. Reason: This candidate is a reservation duplicate of CVE-2024-37295. Notes: All CVE users should reference CVE-2024-37295 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

8.8 High

CVSS3

Дефекты

CWE-434