9.9
CVE-2024-8463
- EPSS 0.11%
- Veröffentlicht 05.09.2024 13:15:12
- Zuletzt bearbeitet 12.09.2024 17:15:02
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phpgurukul ≫ Job Portal Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.291 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| cve-coordination@incibe.es | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.