Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5vc-h7j2-25qc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name>

An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name>

EPSS

Процентиль: 84%
0.02255
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name>

EPSS

Процентиль: 84%
0.02255
Низкий

Дефекты

CWE-434