Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40309
HistoryApr 27, 2023 - 10:07 a.m.

Remote Code Execution (RCE)

2023-04-2710:07:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
remote code execution
ulearnpro/ulearn
image validation
attacker
malicious code
system

EPSS

0.001

Percentile

51.2%

ulearnpro/ulearn is vulnerable to Remote Code Execution (RCE). The vulnerability exists due to the lack of upload image validation, which allows an attacker to upload and execute malicious code on the system.

EPSS

0.001

Percentile

51.2%

Related for VERACODE:40309