Описание
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.
Ссылки
- MitigationThird Party AdvisoryVDB Entry
- MitigationThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:kbvault_mysql_project:kbvault_mysql:0.16a:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.07376
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-732
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.
EPSS
Процентиль: 92%
0.07376
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-732