Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q2hc-xfq6-qp7r

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and filename parameters.

Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and filename parameters.

EPSS

Процентиль: 90%
0.05693
Низкий

8.8 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.8
nvd
больше 9 лет назад

Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and filename parameters.

EPSS

Процентиль: 90%
0.05693
Низкий

8.8 High

CVSS3

Дефекты

CWE-284