Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-1593

Опубликовано: 23 фев. 2025
Источник: nvd
CVSS3: 4.7
CVSS3: 9.8
CVSS2: 5.8
EPSS Низкий

Описание

A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mayurik:best_employee_management_system:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00163
Низкий

4.7 Medium

CVSS3

9.8 Critical

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-284
CWE-434

Связанные уязвимости

CVSS3: 4.7
github
12 месяцев назад

A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.

EPSS

Процентиль: 37%
0.00163
Низкий

4.7 Medium

CVSS3

9.8 Critical

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-284
CWE-434