Описание
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
EPSS
Процентиль: 42%
0.00521
Низкий
7.2 High
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 7.2
github
около 1 месяца назад
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
EPSS
Процентиль: 42%
0.00521
Низкий
7.2 High
CVSS3
Дефекты
CWE-434