Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5fq-p794-xxc8

Опубликовано: 18 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.

College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.

EPSS

Процентиль: 80%
0.01384
Низкий

7.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
nvd
около 3 лет назад

College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.

EPSS

Процентиль: 80%
0.01384
Низкий

7.2 High

CVSS3

Дефекты

CWE-89