Количество 2
Количество 2
CVE-2024-25801
почти 2 года назад
SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not the content) of a file.
CVSS3: 6.1
EPSS: Низкий
GHSA-7r9f-99vw-hx7g
почти 2 года назад
An arbitrary file upload vulnerability in the Add Media function of SKINsoft S-Museum v7.02.3 allows attackers to execute arbitrary code via a crafted PDF file.
CVSS3: 6.1
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-25801 SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not the content) of a file. | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-7r9f-99vw-hx7g An arbitrary file upload vulnerability in the Add Media function of SKINsoft S-Museum v7.02.3 allows attackers to execute arbitrary code via a crafted PDF file. | CVSS3: 6.1 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу
20