Описание
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
Ссылки
- Broken Link
- Broken Link
- ExploitThird Party Advisory
- Broken Link
- Broken Link
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ckeditor:ckeditor:1.2.3:*:*:*:*:redmine:*:*
EPSS
Процентиль: 88%
0.04208
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-434
CWE-434
Связанные уязвимости
CVSS3: 9.8
github
больше 2 лет назад
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
EPSS
Процентиль: 88%
0.04208
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-434
CWE-434