Описание
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler
Ссылки
- Patch
- Release Notes
- MitigationPatch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.5.0 (включая)
cpe:2.3:a:oxygenz:clipbucket:*:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05211
Низкий
7.3 High
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 7.3
github
5 месяцев назад
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler
EPSS
Процентиль: 90%
0.05211
Низкий
7.3 High
CVSS3
Дефекты
CWE-434