vendor:
Flatnux
by:
Ömer Hasan Durmus
7.5
CVSS
HIGH
Remote Code Execution
434
CWE
Product Name: Flatnux
Affected Version From: 2021-03.25
Affected Version To: 2021-03.25
Patch Exists: YES
Related CWE:
CPE: a:altervista:flatnux
Platforms Tested: Windows/Linux
2021
flatnux-2021-03.25 – Remote Code Execution (Authenticated)
A vulnerability in flatnux 2021-03.25 allows an authenticated user to execute arbitrary code by uploading a malicious file via the filemanager.php page. The vulnerability exists due to insufficient validation of user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious code to the vulnerable application. Successful exploitation of this vulnerability could result in remote code execution.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of flatnux.