Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wrpr-q9f3-cqpf

Опубликовано: 01 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.

CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.

EPSS

Процентиль: 68%
0.0056
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
больше 1 года назад

CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.

EPSS

Процентиль: 68%
0.0056
Низкий

7.2 High

CVSS3

Дефекты

CWE-434