Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39345

Опубликовано: 25 окт. 2022
Источник: nvd
CVSS3: 9.8
CVSS3: 7.5
EPSS Низкий

Описание

Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.5.4 contains a patch for this issue. There are no workarounds aside from upgrading to a patched version.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:*
Версия до 2.5.4 (исключая)

EPSS

Процентиль: 72%
0.00739
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Gin-vue-admin subject to Remote Code Execution via file upload vulnerability

EPSS

Процентиль: 72%
0.00739
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22
CWE-22