Описание
This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.
Ссылки
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.7.0 (исключая)
cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.02034
Низкий
8.8 High
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 8.8
github
больше 1 года назад
This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.
EPSS
Процентиль: 83%
0.02034
Низкий
8.8 High
CVSS3
Дефекты
CWE-434