Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhx3-6rjm-4cmc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

EPSS

Процентиль: 99%
0.77029
Высокий

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

EPSS

Процентиль: 99%
0.77029
Высокий