In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Mend
Published: 2022-10-17T18:25:09.233120Z
Updated: 2024-09-17T02:16:38.771Z
Reserved: 2022-05-31T00:00:00
Link: CVE-2022-32176
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-10-17T19:15:09.903
Modified: 2024-11-21T07:05:53.263
Link: CVE-2022-32176
Redhat
No data.