An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.
2024-04-11T06:15:06.903
2025-06-17T20:53:19.370
Analyzed
CVSSv3.1: 7.6 (HIGH)