Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41661

Опубликовано: 13 июн. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:church_management_system_project:church_management_system:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 66%
0.00513
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.

EPSS

Процентиль: 66%
0.00513
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89