Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NDefault status
unaffected
9.0.* (semver)
affected
Description
An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to the server.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
9.0.* (semver)
Credits
Aaron Herndon, Principal Security Consultant, and Marcus Chang, Security Consultant, both of Rapid7.
References
www.rapid7.com/...m-multiple-critical-vulnerabilities-fixed/