Описание
An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file.
Ссылки
- Product
- ExploitIssue TrackingThird Party Advisory
- Product
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:pwndoc_project:pwndoc:0.5.3:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.3031
Средний
8.8 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-434
Связанные уязвимости
CVSS3: 8.8
github
около 3 лет назад
An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file.
EPSS
Процентиль: 97%
0.3031
Средний
8.8 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-434