Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2rh-7rp4-9w6w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.

A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.

EPSS

Процентиль: 59%
0.00378
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
больше 4 лет назад

A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.

EPSS

Процентиль: 59%
0.00378
Низкий

Дефекты

CWE-434