9.8
CVE-2020-24199
- EPSS 3.39%
- Veröffentlicht 09.09.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:14:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Projectworlds ≫ Car Rental Project Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.39% | 0.863 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.