
We found results for “”
CVE-2022-41573
Good to know:

Date: January 6, 2025
An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/common/ URI for remote code execution.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Unrestricted Upload of File with Dangerous Type
CWE-434Top Fix

Upgrade Version
Upgrade to version ovidentia/ovidentia - dev-PATCHS-8-6-0;ovidentia/ovidentia - no_fix;ovidentia/ovidentia - dev-PATCHS-8-5-0;ovidentia/ovidentia - dev-PATCHS-8-4-0;ovidentia/ovidentia - dev-PATCHS-8-3-0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |