Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jmj2-vh9h-r9jp

Опубликовано: 20 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

EPSS

Процентиль: 43%
0.00521
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 1 месяца назад

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

EPSS

Процентиль: 43%
0.00521
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-434