Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2j7-6hxm-87p3

Опубликовано: 02 июл. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Craft CMS Remote Code Injection

An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).

Пакеты

Наименование

craftcms/cms

composer
Затронутые версииВерсия исправления

< 3.6.7

3.6.7

EPSS

Процентиль: 88%
0.03824
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-74
CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).

EPSS

Процентиль: 88%
0.03824
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-74
CWE-94