Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g449-3r9g-f763

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenance Mode setting.

In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenance Mode setting.

EPSS

Процентиль: 75%
0.00873
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenance Mode setting.

EPSS

Процентиль: 75%
0.00873
Низкий