Home

Description

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.

PUBLISHED Reserved 2026-04-13 | Published 2026-06-12 | Updated 2026-06-12 | Assigner TR-CERT




HIGH: 8.7CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Problem types

CWE-434 Unrestricted upload of file with dangerous type

Product status

Default status
unaffected

2.0.9 (custom) before 3.2.45.33
affected

Credits

Hamza Metin GERDAN finder

References

siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0369 government-resource

cve.org (CVE-2026-6211)

nvd.nist.gov (CVE-2026-6211)

Download JSON