CVE-2022-39305
Gin-vue-admin vulnerable to Unrestricted Upload of File with Dangerous Type
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 1.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Oct 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Versions prior to 2.5.4 contain a file upload ability. The affected code fails to validate fileMd5 and fileName parameters, resulting in an arbitrary file being read. This issue is patched in 2.5.4b. There are no known workarounds.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
flipped-aurora · gin-vue-adminWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →