CVE-2017-15054
TeamPass arbitrary file upload vulnerability
7.5
HIGH
CVSS 3.1
EPSS 3.5%
描述
An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to tamper with parameters of a request to upload.files.php, in order to select the correct branch and be able to upload any arbitrary file. From there, it can simply access the file to execute code on the server.
如何修補 CVE-2017-15054
要修補 CVE-2017-15054,請將受影響套件升級到下列已修補版本。
- —升級至 2.1.27.9 或更新版本
CVE-2017-15054 正在被利用嗎?
低 — EPSS 為 3.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.1.27.9
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |