Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pv7w-q9fm-5qf3

Опубликовано: 11 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.

sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.

EPSS

Процентиль: 85%
0.02647
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.

EPSS

Процентиль: 85%
0.02647
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434