Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2w2-352j-xq39

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.5

Описание

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.

EPSS

Процентиль: 72%
0.0074
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 4.5
nvd
больше 20 лет назад

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.

EPSS

Процентиль: 72%
0.0074
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-94