Описание
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.2.2 (исключая)
cpe:2.3:a:tadtools_project:tadtools:*:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.02197
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434
CWE-434
Связанные уязвимости
github
больше 3 лет назад
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.
EPSS
Процентиль: 84%
0.02197
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434
CWE-434