Логотип exploitDog
bind:CVE-2022-50898
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-50898

Количество 2

Количество 2

nvd логотип

CVE-2022-50898

26 дней назад

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-534f-4cxm-43gw

26 дней назад

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-50898

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.

CVSS3: 8.8
0%
Низкий
26 дней назад
github логотип
GHSA-534f-4cxm-43gw

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.

CVSS3: 8.8
0%
Низкий
26 дней назад

Уязвимостей на страницу