Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v96f-fh38-8r85

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The FlashUpload component in Korean GHBoard uses a client-side protection mechanism to prevent uploading of dangerous file extensions, which allows remote attackers to bypass restrictions and upload arbitrary files via a modified copy of component/flashupload/upload.html.

The FlashUpload component in Korean GHBoard uses a client-side protection mechanism to prevent uploading of dangerous file extensions, which allows remote attackers to bypass restrictions and upload arbitrary files via a modified copy of component/flashupload/upload.html.

EPSS

Процентиль: 52%
0.00286
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 18 лет назад

The FlashUpload component in Korean GHBoard uses a client-side protection mechanism to prevent uploading of dangerous file extensions, which allows remote attackers to bypass restrictions and upload arbitrary files via a modified copy of component/flashupload/upload.html.

EPSS

Процентиль: 52%
0.00286
Низкий

Дефекты

CWE-20