Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfh8-7hcx-ppfp

Опубликовано: 04 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.8

Описание

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.

EPSS

Процентиль: 83%
0.02034
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.

EPSS

Процентиль: 83%
0.02034
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434