Описание
The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.
Ссылки
- ProductVendor Advisory
- Third Party Advisory
- ProductVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:vikisolutions:vera:4.9.1.26180:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02631
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434
Связанные уязвимости
github
больше 3 лет назад
The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.
EPSS
Процентиль: 85%
0.02631
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434