Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpvr-w6q5-m4cj

Опубликовано: 24 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.

The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.

EPSS

Процентиль: 80%
0.01392
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.

EPSS

Процентиль: 80%
0.01392
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287