Description
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
Problem types
CWE-434: Unrestricted Upload of File with Dangerous Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-94: Improper Control of Generation of Code ('Code Injection')
Product status
Any version
Credits
Piotr Bazydlo of watchTowr
References
docs.sharefile.com/...oller/5-0/security-vulnerability-feb26