1 results (0.010 seconds)

CVSS: 9.8EPSS: %CPEs: 1EXPL: 1

An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file. Una vulnerabilidad de carga de archivos arbitraria en KYKMS v1.0.1 y versiones anteriores permite a los atacantes ejecutar código arbitrario cargando un archivo PDF manipulado. • https://github.com/Joying-C/Cross-site-scripting-vulnerability/tree/main/KYKMS_Cross_site%20_scripting%20_vulnerability • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-434: Unrestricted Upload of File with Dangerous Type •