CVE-2022-41711

CRITICAL9.8EPSS 10.0%

Badaso vulnerable to Remote Code Execution via malicious file upload

發布日:2022/10/26修改日:2024/2/16

描述

Badaso allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(5)