Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41266
HistoryJul 13, 2023 - 3:53 p.m.

Unrestricted File Upload

2023-07-1315:53:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
file upload checks
low-privileged account
arbitrary php files
software

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.2%

responsive-filemanager,is vulnerable to Unrestricted File Upload. The vulnerability exists due to a lack of file upload checks, which allows an attacker with a low-privileged account to upload and execute arbitrary php files.

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.2%

Related for VERACODE:41266