Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/171542/BoxBilling-4.22.1.5-Remote-Code-Execution.html | |
https://github.com/boxbilling/boxbilling/commit/b6705995785eaa8653e876318c9b3d82060dc945 | Third Party Advisory |
https://huntr.dev/bounties/c6e2973d-386d-4667-9426-10d10828539b | Exploit Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-10-17 21:15
Updated : 2023-03-28 17:15
NVD link : CVE-2022-3552
Mitre link : CVE-2022-3552
CVE.ORG link : CVE-2022-3552
JSON object : View
Products Affected
boxbilling
- boxbilling
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type