Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv23-mm25-48xw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

EPSS

Процентиль: 34%
0.00137
Низкий

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 7.2
nvd
больше 4 лет назад

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

EPSS

Процентиль: 34%
0.00137
Низкий

Дефекты

CWE-345