Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h63m-qhvj-pcgq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.

In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.

EPSS

Процентиль: 84%
0.02121
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.

EPSS

Процентиль: 84%
0.02121
Низкий