Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wjjc-cc9v-hq6j

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 9.8

Описание

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.

EPSS

Процентиль: 59%
0.0038
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.

EPSS

Процентиль: 59%
0.0038
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-434