Логотип exploitDog
bind:CVE-2019-25229
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-25229

Количество 2

Количество 2

nvd логотип

CVE-2019-25229

около 2 месяцев назад

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system, enabling unauthorized file uploads.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-v6gf-3m9q-j3wr

около 2 месяцев назад

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system, enabling unauthorized file uploads.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-25229

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system, enabling unauthorized file uploads.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-v6gf-3m9q-j3wr

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system, enabling unauthorized file uploads.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу