ZeroHour

CVE-2020-36485

PoC
CVSS 3.1
7.8 high
EPSS
<1%p39
Published
()
Modified
Description

Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPEG file.

Vendors
madeportable
Products
playable
Weakness
CWE-434
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.