Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15189

Опубликовано: 18 сент. 2020
Источник: nvd
CVSS3: 6.8
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This vulnerability is caused by insecure configuration in elFinder. This is fixed in version 3.0.2.328.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:brassica:soy_cms:*:*:*:*:*:*:*:*
Версия до 3.0.2.328 (исключая)

EPSS

Процентиль: 89%
0.05039
Низкий

6.8 Medium

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434

EPSS

Процентиль: 89%
0.05039
Низкий

6.8 Medium

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434