Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc96-38mv-g6cc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into the registration form and achieve arbitrary code execution in the context of the admin account.

Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into the registration form and achieve arbitrary code execution in the context of the admin account.

EPSS

Процентиль: 73%
0.00787
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.8
nvd
почти 5 лет назад

Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into an online event form and achieve code execution if the victim exports and opens the data on their local machine.

CVSS3: 8.8
fstec
почти 5 лет назад

Уязвимость программы мгновенного обмена сообщениями Adobe Connect, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 73%
0.00787
Низкий

Дефекты

CWE-20