Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wpgg-qfwq-fwj4

Опубликовано: 16 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image.

Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image.

EPSS

Процентиль: 46%
0.00235
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
почти 2 года назад

Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image.

EPSS

Процентиль: 46%
0.00235
Низкий

8.8 High

CVSS3

Дефекты

CWE-434