Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mfff-pgww-wxxm

Опубликовано: 28 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.

Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.

EPSS

Процентиль: 54%
0.00318
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость микропрограммного обеспечения программируемых контроллеров Saho ADM100 и ADM-100FP, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 54%
0.00318
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434