Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xg84-5464-2qqq

Опубликовано: 22 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files.

Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files.

EPSS

Процентиль: 32%
0.00124
Низкий

8.6 High

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
5 месяцев назад

Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files.

EPSS

Процентиль: 32%
0.00124
Низкий

8.6 High

CVSS4

Дефекты

CWE-434