Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-27964

Опубликовано: 05 мар. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Высокий

Описание

SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sfcyazilim:sonlogger:*:*:*:*:*:*:*:*
Версия до 6.4.1 (исключая)

EPSS

Процентиль: 99%
0.8087
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434

Связанные уязвимости

github
больше 3 лет назад

SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

EPSS

Процентиль: 99%
0.8087
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-434