Опубликовано: 20 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2
Описание
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
Связанные уязвимости
CVSS3: 7.2
nvd
21 день назад
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.