Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vm4j-2mrw-2c59

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

EPSS

Процентиль: 79%
0.01305
Низкий

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

EPSS

Процентиль: 79%
0.01305
Низкий

Дефекты

CWE-918