Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3771

Опубликовано: 31 окт. 2022
Источник: nvd
CVSS3: 6.3
CVSS3: 9.8
EPSS Низкий

Описание

A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of the file helpers/Upload.php of the component File Upload Management. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The identifier VDB-212501 was assigned to this vulnerability.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:easyiicms:easyiicms:-:*:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.00247
Низкий

6.3 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-266
CWE-434

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

easyii CMS's File Upload Management vulnerable to unrestricted upload

EPSS

Процентиль: 48%
0.00247
Низкий

6.3 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-266
CWE-434