Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m278-c6gg-4jrr

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.1

Описание

TYPO3 powermail extension has unrestricted file upload vulnerability

Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted extension, then accessing it via unspecified vectors.

Пакеты

Наименование

in2code/powermail

composer
Затронутые версииВерсия исправления

< 1.6.11

1.6.11

Наименование

in2code/powermail

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.14

2.0.14

EPSS

Процентиль: 82%
0.01727
Низкий

8.1 High

CVSS4

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 11 лет назад

Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted extension, then accessing it via unspecified vectors.

nvd
больше 11 лет назад

Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted extension, then accessing it via unspecified vectors.

EPSS

Процентиль: 82%
0.01727
Низкий

8.1 High

CVSS4

Дефекты

CWE-94