Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-48646

Опубликовано: 30 окт. 2024
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files, such as HTML, scripts, or other executable content, that may be executed on the server, leading to further system compromise.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sage:sage_frp_1000:7.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 28%
0.00101
Низкий

8.1 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.1
github
больше 1 года назад

An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files, such as HTML, scripts, or other executable content, that may be executed on the server, leading to further system compromise.

EPSS

Процентиль: 28%
0.00101
Низкий

8.1 High

CVSS3

Дефекты

CWE-434