Описание
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.
Ссылки
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.6.6 (включая)
cpe:2.3:a:icz:matcha_invoice:*:*:*:*:*:*:*:*
EPSS
Процентиль: 14%
0.00228
Низкий
4.7 Medium
CVSS3
7.2 High
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 4.7
github
6 месяцев назад
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.
EPSS
Процентиль: 14%
0.00228
Низкий
4.7 Medium
CVSS3
7.2 High
CVSS3
Дефекты
CWE-434