Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq44-hr9j-8673

Опубликовано: 04 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

EPSS

Процентиль: 65%
0.00496
Низкий

7.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.8
nvd
больше 2 лет назад

An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

EPSS

Процентиль: 65%
0.00496
Низкий

7.8 High

CVSS3

Дефекты

CWE-434