Логотип exploitDog
bind:CVE-2020-26804
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26804

Количество 2

Количество 2

nvd логотип

CVE-2020-26804

около 5 лет назад

In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-6jgh-69hg-fvcw

больше 3 лет назад

In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26804

In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.

CVSS3: 8.8
0%
Низкий
около 5 лет назад
github логотип
GHSA-6jgh-69hg-fvcw

In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу