Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40304
HistoryApr 27, 2023 - 5:06 a.m.

Remote Code Execution (RCE)

2023-04-2705:06:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4
remote code execution
vulnerability
profile pictures
software

0.001 Low

EPSS

Percentile

46.5%

uvdesk/community-skeleton is vulnerable to Remote Code Execution. The vulnerability exists because the library does not properly validate uploaded profile pictures, allowing an attacker to upload and execute a malicious file.

0.001 Low

EPSS

Percentile

46.5%

Related for VERACODE:40304