What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.
Explanation of Vulnerability in Simple Terms
Rencontre – Dating Site versions up to 3.10.1 allow unauthenticated attackers to upload files without restriction. An attacker can upload malicious files (such as PHP scripts) directly to the site, gaining the ability to run their own code and take full control. No user interaction or authentication is required.
What an attacker can do
Upload and execute malicious files to run arbitrary code on the site.
Potential impact on your site
Complete site compromise: attackers can read/modify/delete data, steal credentials, and redirect users.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities