Описание
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.0.1 (исключая)
cpe:2.3:a:glpi-project:positions:*:*:*:*:*:glpi:*:*
EPSS
Процентиль: 95%
0.17666
Средний
9.8 Critical
CVSS3
Дефекты
CWE-434
CWE-434
Связанные уязвимости
CVSS3: 9.8
github
почти 3 года назад
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
EPSS
Процентиль: 95%
0.17666
Средний
9.8 Critical
CVSS3
Дефекты
CWE-434
CWE-434