Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j63w-3qvx-6842

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files and leading to privilege escalation or remote code execution.

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files and leading to privilege escalation or remote code execution.

EPSS

Процентиль: 60%
0.00402
Низкий

8.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
nvd
2 месяца назад

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files and leading to privilege escalation or remote code execution.

EPSS

Процентиль: 60%
0.00402
Низкий

8.8 High

CVSS3

Дефекты

CWE-22