Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvhx-qhmq-cpjp

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code.

PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code.

EPSS

Процентиль: 60%
0.00397
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code.

EPSS

Процентиль: 60%
0.00397
Низкий

Дефекты

CWE-434