Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prj7-gm8m-736f

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.

An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.

EPSS

Процентиль: 47%
0.00241
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.

EPSS

Процентиль: 47%
0.00241
Низкий

8.8 High

CVSS3

Дефекты

CWE-434