Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfg2-33mf-746p

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

EPSS

Процентиль: 98%
0.60269
Средний

Дефекты

CWE-74

Связанные уязвимости

nvd
около 10 лет назад

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

msrc
3 месяца назад

The theme editor in Bolt allows remote authenticated users to execute arbitrary code by renaming a crafted file

EPSS

Процентиль: 98%
0.60269
Средний

Дефекты

CWE-74