Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jfcq-6qwc-xqvx

Опубликовано: 27 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.

A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.

EPSS

Процентиль: 39%
0.00171
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-347

Связанные уязвимости

nvd
около 1 года назад

A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.

EPSS

Процентиль: 39%
0.00171
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-347