Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2vj-428g-v68v

Опубликовано: 20 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows

Remote Code Execution

via specific file types

Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows

Remote Code Execution

via specific file types

EPSS

Процентиль: 74%
0.0085
Низкий

8.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.2
nvd
больше 2 лет назад

Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types

EPSS

Процентиль: 74%
0.0085
Низкий

8.2 High

CVSS3

Дефекты

CWE-434