Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wg9c-53cp-4j79

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.

OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.

EPSS

Процентиль: 84%
0.02284
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 5 лет назад

OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.

EPSS

Процентиль: 84%
0.02284
Низкий

Дефекты

CWE-434