Описание
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server.This issue affects Rental Module: before 23.05.15.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 23.05.15 (исключая)
cpe:2.3:a:rental_module_project:rental_module:*:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.0027
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 10
github
больше 2 лет назад
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server.This issue affects Rental Module: before 23.05.15.
EPSS
Процентиль: 50%
0.0027
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-434