Описание
ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.
Ссылки
- ExploitThird Party Advisory
- ExploitIssue TrackingVendor Advisory
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.246 (включая)
cpe:2.3:a:processwire:processwire:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00058
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-400
Связанные уязвимости
github
4 месяца назад
ProcessWire CMS vulnerable to resource-exhaustion Denial of Service
EPSS
Процентиль: 18%
0.00058
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-400