Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28435

Опубликовано: 24 мар. 2023
Источник: nvd
CVSS3: 6.5
CVSS3: 6.1
EPSS Низкий

Описание

Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulnerabilities has been fixed in version 1.18.5.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
Версия до 1.18.5 (исключая)

EPSS

Процентиль: 55%
0.0033
Низкий

6.5 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 55%
0.0033
Низкий

6.5 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79