Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vhmq-vxfx-c9h8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.

Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.

EPSS

Процентиль: 92%
0.0787
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.

EPSS

Процентиль: 92%
0.0787
Низкий

Дефекты

CWE-434