Количество 2
Количество 2
CVE-2022-23043
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.
GHSA-6r86-2jm9-9mh4
File upload restriction bypass in Zenario CMS
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-23043 Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server. | CVSS3: 7.2 | 1% Низкий | почти 4 года назад | |
GHSA-6r86-2jm9-9mh4 File upload restriction bypass in Zenario CMS | CVSS3: 7.2 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу