Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-24984

Опубликовано: 16 фев. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 6.8
EPSS Низкий

Описание

Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all executable content (e.g., .phtml or .php.bak) is blocked.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jqueryform:jqueryform:*:*:*:*:*:*:*:*
Версия до 2022-02-05 (исключая)

EPSS

Процентиль: 85%
0.02427
Низкий

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

github
почти 4 года назад

Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all executable content (e.g., .phtml or .php.bak) is blocked.

EPSS

Процентиль: 85%
0.02427
Низкий

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-434