Описание
A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.
EPSS
Процентиль: 7%
0.00027
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-646
Связанные уязвимости
CVSS3: 4.3
github
4 месяца назад
A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.
EPSS
Процентиль: 7%
0.00027
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-646