Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whwv-236h-fxh5

Опубликовано: 31 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.5

Описание

Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a product user, an arbitrary script may be executed on the browser.

Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a product user, an arbitrary script may be executed on the browser.

EPSS

Процентиль: 7%
0.00027
Низкий

5.1 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.5
nvd
6 месяцев назад

Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a product user, an arbitrary script may be executed on the browser.

EPSS

Процентиль: 7%
0.00027
Низкий

5.1 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-434