Логотип exploitDog
bind:CVE-2023-53950
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53950

Количество 2

Количество 2

nvd логотип

CVE-2023-53950

около 2 месяцев назад

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cjf9-p6jj-3g6r

около 2 месяцев назад

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53950

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-cjf9-p6jj-3g6r

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу