Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j942-4f9w-rfqh

Опубликовано: 22 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.

A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.

EPSS

Процентиль: 7%
0.00027
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-646

Связанные уязвимости

CVSS3: 4.3
nvd
4 месяца назад

A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.

EPSS

Процентиль: 7%
0.00027
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-646