Lucene search

K
nvd[email protected]NVD:CVE-2022-2751
HistoryAug 11, 2022 - 5:15 a.m.

CVE-2022-2751

2022-08-1105:15:08
CWE-434
web.nvd.nist.gov
3
vulnerability
sourcecodester cms
unrestricted upload

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.7%

A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-206024.

Affected configurations

Nvd
Node
company_website_cms_projectcompany_website_cmsMatch-
VendorProductVersionCPE
company_website_cms_projectcompany_website_cms-cpe:2.3:a:company_website_cms_project:company_website_cms:-:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.7%

Related for NVD:CVE-2022-2751