Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3x7-xjfr-2hfx

Опубликовано: 13 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to write) resulting a remote code execution.

RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to write) resulting a remote code execution.

EPSS

Процентиль: 81%
0.01468
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to write) resulting a remote code execution.

EPSS

Процентиль: 81%
0.01468
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22