Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-66686
HistoryMay 25, 2022 - 12:00 a.m.

Publify arbitrary file upload vulnerability

2022-05-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
publify
file upload
vulnerability
validation
malicious files
arbitrary code
execution

EPSS

0.001

Percentile

21.4%

Publify is a simple but full-featured web publishing software.An arbitrary file upload vulnerability exists in versions of Publify prior to 9.2.9, which stems from the application’s lack of validation of uploaded files. An attacker could exploit this vulnerability to upload malicious files to remotely execute arbitrary code.

EPSS

0.001

Percentile

21.4%