Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40889

Опубликовано: 11 окт. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents() function to write username in password.php file when a user successfully changed their password. The attacker can inject malicious PHP code into password.php and then use the login function to execute code.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cmsuno_project:cmsuno:1.7.2:*:*:*:*:*:*:*

EPSS

Процентиль: 60%
0.00396
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
больше 3 лет назад

CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents() function to write username in password.php file when a user successfully changed their password. The attacker can inject malicious PHP code into password.php and then use the login function to execute code.

EPSS

Процентиль: 60%
0.00396
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-94