Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r72h-j3wg-jrp4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

EPSS

Процентиль: 78%
0.0111
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

EPSS

Процентиль: 78%
0.0111
Низкий

Дефекты

CWE-434