8.8
CVSSv3

CVE-2018-16796

Published: 13/09/2018 Updated: 25/11/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

HiScout GRC Suite prior to 3.1.5 allows Unrestricted Upload of Files with Dangerous Types.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hiscout grc suite

Exploits

HiScout GRC Suite versions prior to 315 suffer from a file upload vulnerability An authenticated attacker with the permission to edit or add a "WebSiteElement" to the "content" pages is able to upload any file with any file extension to the data directory of the application This directory is in the web root and the uploaded file is executed on ...