vendor:
CI User Login and Management
by:
Ihsan Sencan
7.5
CVSS
HIGH
Arbitrary File Upload
CWE
Product Name: CI User Login and Management
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 64-bit and Kali Linux 64-bit
2018
CI User Login and Management 1.0 – Arbitrary File Upload
The CI User Login and Management 1.0 software allows an attacker to upload arbitrary files to the server. This can lead to remote code execution and other unauthorized activities.
Mitigation:
The vendor should release a patch to fix the vulnerability. In the meantime, users should restrict access to the vulnerable software and apply other security measures like input validation and file type restrictions.