Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vqvm-qrwh-69h7

Опубликовано: 31 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

easyii CMS's File Upload Management vulnerable to unrestricted upload

This issue affects the function file of the file helpers/Upload.php of the component File Upload Management. The manipulation leads to unrestricted upload. The attack may be initiated remotely.

Пакеты

Наименование

noumo/easyii

composer
Затронутые версииВерсия исправления

<= 0.9

Отсутствует

EPSS

Процентиль: 48%
0.00247
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-434

Связанные уязвимости

CVSS3: 6.3
nvd
больше 3 лет назад

A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of the file helpers/Upload.php of the component File Upload Management. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The identifier VDB-212501 was assigned to this vulnerability.

EPSS

Процентиль: 48%
0.00247
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-434