Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xhhh-8cg4-rhc7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

EPSS

Процентиль: 67%
0.00537
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

EPSS

Процентиль: 67%
0.00537
Низкий

Дефекты

CWE-434