CVE-2021-3745 Information
Jun 07, 2022
cve
Description
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://huntr.dev/bounties/7879ab3d-8018-402a-aa0b-131bdbd1966c https://github.com/flatcore/flatcore-cms/commit/5cc3937b6bc38293ec921a5cf00018b48b668dc6
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
6.6
Share on: