Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prcg-jvr3-4cwr

Опубликовано: 01 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip file through the plugin upload component. The exploitation of this vulnerability could lead to a remote code injection.

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip file through the plugin upload component. The exploitation of this vulnerability could lead to a remote code injection.

EPSS

Процентиль: 72%
0.00709
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.9
nvd
больше 3 лет назад

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip file through the plugin upload component. The exploitation of this vulnerability could lead to a remote code injection.

EPSS

Процентиль: 72%
0.00709
Низкий

8.8 High

CVSS3

Дефекты

CWE-434