Описание
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
Ссылки
- Broken Link
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Broken Link
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:kea-hotel-erp_project:kea-hotel-erp:-:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.03029
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434
Связанные уязвимости
github
около 4 лет назад
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
EPSS
Процентиль: 86%
0.03029
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434