Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w9qq-jmgq-wfv5

Опубликовано: 29 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

EPSS

Процентиль: 85%
0.02684
Низкий

8.8 High

CVSS3

Дефекты

CWE-24

Связанные уязвимости

CVSS3: 8.8
nvd
6 месяцев назад

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

EPSS

Процентиль: 85%
0.02684
Низкий

8.8 High

CVSS3

Дефекты

CWE-24