Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2v6-jq3p-wj4f

Опубликовано: 30 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A vulnerability classified as critical has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected is an unknown function of the file admin/products/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. VDB-224622 is the identifier assigned to this vulnerability.

A vulnerability classified as critical has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected is an unknown function of the file admin/products/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. VDB-224622 is the identifier assigned to this vulnerability.

EPSS

Процентиль: 24%
0.0008
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.3
nvd
почти 3 года назад

A vulnerability classified as critical has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected is an unknown function of the file admin/products/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. VDB-224622 is the identifier assigned to this vulnerability.

EPSS

Процентиль: 24%
0.0008
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434