Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-59198
HistoryAug 24, 2022 - 12:00 a.m.

BaijiaCMS arbitrary file upload vulnerability

2022-08-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
baijiacms
java quest
file upload
validation
vulnerability
remote code execution

EPSS

0.003

Percentile

71.7%

BaijiaCMS, a Java Quest soft player from BaijiaCMS, has an arbitrary file upload vulnerability in BaijiaCMS v4, which stems from the application’s lack of validation of uploaded files. An attacker could exploit this vulnerability to upload malicious files to remotely execute arbitrary code.

EPSS

0.003

Percentile

71.7%

Related for CNVD-2022-59198