9.8

CVE-2024-25182

Exploit
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VvvebVvvebjs Version1.7.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.249
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://gist.github.com/joaoviictorti/ff6220d8ed6df77a0420f4413a1d9b8d
Exploit
Issue Tracking