Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpj8-xfqc-jcv9

Опубликовано: 14 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Cockpit CMS contains an arbitrary file upload vulenrability

A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.

Пакеты

Наименование

cockpit-hq/cockpit

composer
Затронутые версииВерсия исправления

< 2.7.0

2.7.0

EPSS

Процентиль: 29%
0.00104
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.

EPSS

Процентиль: 29%
0.00104
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434