Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mxm8-cmpq-g5cx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

EPSS

Процентиль: 99%
0.82126
Высокий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

EPSS

Процентиль: 99%
0.82126
Высокий

Дефекты

CWE-434