Логотип exploitDog
bind:CVE-2022-1411
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-1411

Количество 2

Количество 2

nvd логотип

CVE-2022-1411

почти 4 года назад

Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-pqr6-3j58-9w58

почти 4 года назад

Unrestricted Upload of File with Dangerous Type in yetiforce-crm

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-1411

Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-pqr6-3j58-9w58

Unrestricted Upload of File with Dangerous Type in yetiforce-crm

CVSS3: 6.1
0%
Низкий
почти 4 года назад

Уязвимостей на страницу