Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-29770
HistoryNov 28, 2023 - 12:15 a.m.

Design/Logic Flaw

2023-11-2800:15:00
PRIOn knowledge base
www.prio-n.com
2
sentrifugo
assetscontroller
uploadsaveaction
logic flaw
unauthorized file uploads

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.3%

In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension filtering.

CPENameOperatorVersion
sentrifugoeq3.5

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.3%

Related for PRION:CVE-2023-29770