Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47655

Опубликовано: 04 окт. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*
Версия до 9.7.0 (исключая)

EPSS

Процентиль: 83%
0.02034
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
github
больше 1 года назад

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.

EPSS

Процентиль: 83%
0.02034
Низкий

8.8 High

CVSS3

Дефекты

CWE-434