ZeroHour

CVE-2020-24984

PoC
CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
Description

An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicious files to the web server.

Vendors
quadbase
Products
espressreports es
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news