Overview
- Description
- An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfileupload function, due to the lack of proper file type validation controls, resulting in a full system compromise.
- Source
- cve-coordination@incibe.es
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Weaknesses
- cve-coordination@incibe.es
- CWE-434
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:europeana:repox:2.3.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA4CFB07-33A3-44FB-A484-9C23CD4AA5B3" } ], "operator": "OR" } ] } ]