Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g497-rhxm-mc9f

Опубликовано: 23 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.

Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.

EPSS

Процентиль: 73%
0.00778
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.

EPSS

Процентиль: 73%
0.00778
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434