Описание
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.
Ссылки
- Broken Link
- ExploitMitigationThird Party Advisory
- Broken Link
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:academiaerp:student_information_system:eagler-1.0.118:*:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.009
Низкий
6.4 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-24
Связанные уязвимости
CVSS3: 6.4
github
10 месяцев назад
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.
EPSS
Процентиль: 75%
0.009
Низкий
6.4 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-24