Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2606

Опубликовано: 21 мар. 2025
Источник: nvd
CVSS3: 6.3
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/soulwinning_crud.php. The manipulation of the argument photo/photo1 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mayurik:best_church_management_software:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 29%
0.00101
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-284
CWE-434

Связанные уязвимости

CVSS3: 6.3
github
11 месяцев назад

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/soulwinning_crud.php. The manipulation of the argument photo/photo1 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 29%
0.00101
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-284
CWE-434