Bettershop LaikeTui POST Request index.php?module=api&action=user&m=upload ebisanyizo ebyongerwako
| CVSS Obubonero bwa Meta Temp | Ekikadde ky’omuwendo gw’okukozesa obunafu obuliko kati (≈) | CTI Ennyanja y'okukwata ku nsonga |
|---|---|---|
| 7.4 | $0-$5k | 0.18 |
Okusumulula
Waliwo obulabe obwategekeddwa nga kizibu obuzuliddwa mu Bettershop LaikeTui. Obulabe buli ku omugaso ogutamanyiddwa ku fayiro index.php?module=api&action=user&m=upload ku kitundu POST Request Handler. Okukozesa kivirako ebisanyizo ebyongerwako. Obunafu buno buzibwa nga CVE-2023-4559. Kisoboka okutandika okukola attack okuva wala. Wabula, tewali kikozesebwa kiriwo. Ekikozesebwa kino kisindika rolling release okutuusa obuweereza obutayimirira. Noolwekyo, tewali makulu ga version ku bitundu ebyakosebwa oba ebyateekebwako enkyukakyuka agaliwo. If you want to get best quality of vulnerability data, you may have to visit VulDB.
Ebirimu
Waliwo obulabe obwategekeddwa nga kizibu obuzuliddwa mu Bettershop LaikeTui. Obulabe buli ku omugaso ogutamanyiddwa ku fayiro index.php?module=api&action=user&m=upload ku kitundu POST Request Handler. Okukozesa kivirako ebisanyizo ebyongerwako. Okukozesa CWE okulaga ekizibu kireetera CWE-434. Obunafu buno bwateekebwawo ku 27/08/2023.
Obunafu buno buzibwa nga CVE-2023-4559. Kisoboka okutandika okukola attack okuva wala. Obulambulukufu bw'eby'ekikugu buliwo. Obukadde bw'ensobi eno buli wansi w'ekigero ekisookerwako. Wabula, tewali kikozesebwa kiriwo. Mu kiseera kino, omutengo ogw’akaseera ku kikozesebwa kiyinza okuba nga giri mu USD $0-$5k mu kiseera kino.
Kitegekeddwa nga tekitegedde. Ng’era 0-day, omuwendo ogusabibwa mu kifo ky’obutali mu mateeka gwali nga wa ddala $0-$5k.
Ekikozesebwa kino kisindika rolling release okutuusa obuweereza obutayimirira. Noolwekyo, tewali makulu ga version ku bitundu ebyakosebwa oba ebyateekebwako enkyukakyuka agaliwo.
If you want to get best quality of vulnerability data, you may have to visit VulDB.
Ekitundu
Omukola
Erinnya
CPE 2.3
CPE 2.2
CVSSv4
VulDB Ekikunta: 🔍VulDB Reliability: 🔍
CVSSv3
VulDB Obubonero Obusookerwako Obw'enkizo: 7.5VulDB Obubonero bwa Meta Temp: 7.4
VulDB Obubonero Obusookerwako: 6.3
VulDB Obubonero bw’akaseera: 6.1
VulDB Ekikunta: 🔍
VulDB Reliability: 🔍
NVD Obubonero Obusookerwako: 9.8
NVD Ekikunta: 🔍
CNA Obubonero Obusookerwako: 6.3
CNA Ekikunta (VulDB): 🔍
CVSSv2
| AV | AC | Au | C | I | A |
|---|---|---|---|---|---|
| 💳 | 💳 | 💳 | 💳 | 💳 | 💳 |
| 💳 | 💳 | 💳 | 💳 | 💳 | 💳 |
| 💳 | 💳 | 💳 | 💳 | 💳 | 💳 |
| Ekikozesebwa | Obuzibu obungi | Okukakasa obutuufu bw'omuntu | Obukakafu | Obutebenkevu | Okusobola okufuna (Obusobozi obw'okufuna) |
|---|---|---|---|---|---|
| okuyimbula | okuyimbula | okuyimbula | okuyimbula | okuyimbula | okuyimbula |
| okuyimbula | okuyimbula | okuyimbula | okuyimbula | okuyimbula | okuyimbula |
| okuyimbula | okuyimbula | okuyimbula | okuyimbula | okuyimbula | okuyimbula |
VulDB Obubonero Obusookerwako: 🔍
VulDB Obubonero bw’akaseera: 🔍
VulDB Reliability: 🔍
NVD Obubonero Obusookerwako: 🔍
Okukozesa obunafu
Ekibiina: Ebisanyizo ebyongerwakoCWE: CWE-434 / CWE-284 / CWE-266
CAPEC: 🔍
ATT&CK: 🔍
Obulamu obw’omubiri: Nedda
Wansi wano: Nedda
Waliwo okuva wala: Wee
Okusobola okufuna (Obusobozi obw'okufuna): 🔍
Embeera: Tekitegedde
EPSS Score: 🔍
EPSS Percentile: 🔍
Okukulaakulana kw'ebisale: 🔍
Okubala okw’ensimbi okw’akatono okuva mu kiseera kino: 🔍
| 0-Day | okuyimbula | okuyimbula | okuyimbula | okuyimbula |
|---|---|---|---|---|
| Leero | okuyimbula | okuyimbula | okuyimbula | okuyimbula |
Amagezi ku bulabe
Okukwata ku: 🔍Abakola abali mu kikolwa: 🔍
Ebibiina bya APT ebikola kaakano: 🔍
Ebyokukwata ku kwekuumira
Okukakasa: Tewali kikolebwa kimanyiddwaEmbeera: 🔍
Ekiseera kya 0-Day: 🔍
Ekiseera ekyayita
27/08/2023 🔍27/08/2023 🔍
27/08/2023 🔍
20/09/2023 🔍
Ebyokutwalira
Embeera: TekitegeddeCVE: CVE-2023-4559 (🔍)
GCVE (CVE): GCVE-0-2023-4559
GCVE (VulDB): GCVE-100-238160
Okuyingiza
Kikolebwa: 27/08/2023 08:20Okukozesa enkola empya: 20/09/2023 18:10
Okukyuusa: 27/08/2023 08:20 (37), 20/09/2023 18:02 (2), 20/09/2023 18:10 (28)
Kituufu ddala: 🔍
Owoleza: p1nk
Cache ID: 253:47B:103
Twasiriza
Kikkiriziddwa
- Twasiriza #198895: The laiketui program has a remote code execution vulnerability (kuva p1nk)
Tewali biragiddwaako kati. Enimi: lg + en.
Nsaba yingira mu akaawunti yo osobole okwogera.