Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8940

Опубликовано: 25 сент. 2024
Источник: nvd
CVSS3: 10
CVSS3: 9.8
EPSS Низкий

Описание

Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:scriptcase:scriptcase:9.4.019:*:*:*:*:*:*:*

EPSS

Процентиль: 30%
0.00113
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 10
github
больше 1 года назад

Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.

EPSS

Процентиль: 30%
0.00113
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-434