9.8
CVE-2021-45835
- EPSS 22.21%
- Veröffentlicht 18.03.2022 11:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Online Admission System Project ≫ Online Admissions System Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 22.21% | 0.956 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.