Description
An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to the server.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
9.0.*
Credits
Aaron Herndon, Principal Security Consultant, and Marcus Chang, Security Consultant, both of Rapid7.
References
www.rapid7.com/...m-multiple-critical-vulnerabilities-fixed/