Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8vj-85m9-crfq

Опубликовано: 16 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file.

An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file.

EPSS

Процентиль: 69%
0.00593
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 года назад

An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file.

EPSS

Процентиль: 69%
0.00593
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-434