Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jv2q-4pxc-v47p

Опубликовано: 28 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Gym Management System Project v1.0 is vulnerable to

an Insecure File Upload vulnerability on the 'file'

parameter of profile/i.php page, allowing an

authenticated attacker to obtain Remote Code Execution

on the server hosting the application.

Gym Management System Project v1.0 is vulnerable to

an Insecure File Upload vulnerability on the 'file'

parameter of profile/i.php page, allowing an

authenticated attacker to obtain Remote Code Execution

on the server hosting the application.

EPSS

Процентиль: 80%
0.01427
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.1
nvd
больше 2 лет назад

Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

EPSS

Процентиль: 80%
0.01427
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-434