Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9w7-v37j-9778

Опубликовано: 18 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler

EPSS

Процентиль: 90%
0.05211
Низкий

7.3 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.3
nvd
5 месяцев назад

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler

EPSS

Процентиль: 90%
0.05211
Низкий

7.3 High

CVSS3

Дефекты

CWE-434