Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m525-p4rf-7h93

Опубликовано: 29 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.5

Описание

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

EPSS

Процентиль: 41%
0.0019
Низкий

3.5 Low

CVSS3

Дефекты

CWE-20
CWE-354

Связанные уязвимости

CVSS3: 3.5
ubuntu
около 2 лет назад

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

CVSS3: 3.5
nvd
около 2 лет назад

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

CVSS3: 9.8
fstec
около 2 лет назад

Уязвимость функции загрузки аватаров пользователей системы обработки заявок OTRS, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 41%
0.0019
Низкий

3.5 Low

CVSS3

Дефекты

CWE-20
CWE-354