Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gr6q-m3p4-m22c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.

EPSS

Процентиль: 52%
0.00289
Низкий

Дефекты

CWE-706

Связанные уязвимости

CVSS3: 9.1
nvd
больше 4 лет назад

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.

CVSS3: 6.3
fstec
больше 4 лет назад

Уязвимость функции unlink() системы управления контентом CSZ CMS, позволяющая нарушителю удалять произвольные файлы

EPSS

Процентиль: 52%
0.00289
Низкий

Дефекты

CWE-706