Описание
Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload different file extensions without any restrictions, resulting in a full system compromise.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cires21:live_encoder:5.3:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00436
Низкий
10 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 10
github
около 2 лет назад
Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload different file extensions without any restrictions, resulting in a full system compromise.
EPSS
Процентиль: 62%
0.00436
Низкий
10 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-434