CVE-2023-5919

Severity
7.2HIGH
EPSS
0.1%
top 80.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2

Description

A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-244310 is the identifier assigned to this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LExploitability: 1.2 | Impact: 3.4

🔴Vulnerability Details

2
GHSA
GHSA-58cf-923h-gc5m: A vulnerability was found in SourceCodester Company Website CMS 12023-11-02
CVEList
SourceCodester Company Website CMS Create Blog Page createblog unrestricted upload2023-11-02
CVE-2023-5919 (HIGH CVSS 7.2) | A vulnerability was found in Source | cvebase.io