8.8
CVSSv3

CVE-2017-14840

Published: 28/09/2017 Updated: 06/10/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.

Vulnerable Product Search on Vulmon Subscribe to Product

teamworktec ticketplus -

Exploits

# # # # # # Exploit Title: TicketPlus - Support Ticket Management System - Arbitrary File Upload # Dork: N/A # Date: 26092017 # Vendor Homepage: teamworkteccom/ # Software Link: codecanyonnet/item/ticketplus-support-ticket-management-system/20221316 # Demo: sportsgrandcom/demo/ticket_plus/ # Version: N/A # Category: Weba ...