Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mf5w-j54p-pxmp

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the captcha parameter to module.php, as demonstrated by cross-site request forgery (CSRF) attacks.

Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the captcha parameter to module.php, as demonstrated by cross-site request forgery (CSRF) attacks.

EPSS

Процентиль: 59%
0.00388
Низкий

Дефекты

CWE-22

Связанные уязвимости

nvd
больше 13 лет назад

Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the captcha parameter to module.php, as demonstrated by cross-site request forgery (CSRF) attacks.

EPSS

Процентиль: 59%
0.00388
Низкий

Дефекты

CWE-22