Описание
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitIssue TrackingThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:simple_chatbot_application_project:simple_chatbot_application:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.02702
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434
Связанные уязвимости
github
около 4 лет назад
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.
EPSS
Процентиль: 86%
0.02702
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434