Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-30248

Опубликовано: 02 апр. 2024
Источник: nvd
CVSS3: 7.7
EPSS Низкий

Описание

Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As a default, SVG is an allowed file type for upload. An attacker can upload an SVG which when loaded can allow arbitrary access to the admin page. This vulnerability was patched in version 1.3.2.

EPSS

Процентиль: 28%
0.00098
Низкий

7.7 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.7
github
почти 2 года назад

Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page

EPSS

Процентиль: 28%
0.00098
Низкий

7.7 High

CVSS3

Дефекты

CWE-79