Описание
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.
Ссылки
- Not Applicable
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:carmelo:computer_laboratory_system:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 14%
0.00046
Низкий
7.3 High
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 7.3
github
5 месяцев назад
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.
EPSS
Процентиль: 14%
0.00046
Низкий
7.3 High
CVSS3
Дефекты
CWE-434