Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r46w-6r25-mwj8

Опубликовано: 15 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server.

WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server.

EPSS

Процентиль: 53%
0.00303
Низкий

8.7 High

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
около 2 месяцев назад

WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server.

EPSS

Процентиль: 53%
0.00303
Низкий

8.7 High

CVSS4

Дефекты

CWE-434