VYPR

Rukovoditel

by Dmitrybuhtiyarov

CVEs (1)

  • CVE-2018-20166Jan 2, 2019
    risk 0.03cvss epss 0.07

    A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. It accepts uploads of PHP content if the first few characters match GIF data, and the filename ends in…