Products

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
gmapfp vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

gmapfp gmapfp Unrestricted Upload of File with Dangerous Type

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

CWE-434Aug 27, 20201 related artifact
CVSS7.5v3.1EPSS31.4%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX