Логотип exploitDog
bind:CVE-2019-12150
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-12150

Количество 2

Количество 2

nvd логотип

CVE-2019-12150

больше 6 лет назад

Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-qf2m-h28q-74r5

больше 3 лет назад

Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-12150

Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
github логотип
GHSA-qf2m-h28q-74r5

Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEditorInclude/UserFiles/ URI.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу