MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.
Score: 3.25
Priority: P2 - Serious (High)
Score: 0.18438
Percentile:
0.94936
CVSS v3.1 Score: 7.5
Severity: HIGH