8.8

CVE-2023-0455

Exploit

Unrestricted Upload of File with Dangerous Type in unilogies/bumsys

Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bumsys ProjectBumsys Version1.0.0 Updatebeta
Bumsys ProjectBumsys Version1.0.1
Bumsys ProjectBumsys Version1.0.2 Updatebeta
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.75% 0.921
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@huntr.dev 7.6 2.8 4.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

http://packetstormsecurity.com/files/172674/Bumsys-Business-Management-System-1.0.3-beta-Shell-Upload.html
https://github.com/unilogies/bumsys/commit/a5beff7868ab63bf4ec752a1102f8da033c66b28
Patch
Third Party Advisory
https://huntr.dev/bounties/b5e9c578-1a33-4745-bf6b-e7cdb89793f7
Patch
Third Party Advisory
Exploit