CVE-2022-39305

CRITICAL

Gin-vue-admin < 2.5.4b - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Versions prior to 2.5.4 contain a file upload ability. The affected code fails to validate fileMd5 and fileName parameters, resulting in an arbitrary file being read. This issue is patched in 2.5.4b. There are no known workarounds.

Scores

CVSS v3 9.8
EPSS 0.0045
EPSS Percentile 63.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
gin-vue-admin_project/gin-vue-admin < 2.5.4b
Published Oct 24, 2022
Tracked Since Feb 18, 2026