vendor:
FestOS
by:
Unknown
7.5
CVSS
HIGH
Arbitrary File Upload
Unknown
CWE
Product Name: FestOS
Affected Version From: FestOS 2.3c
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:festos:festos:2.3c
Platforms Tested: Unknown
Unknown
Arbitrary File Upload vulnerability in FestOS
The FestOS application fails to sanitize user-supplied input, allowing an attacker to upload arbitrary code and run it in the context of the webserver process. This can lead to remote code execution and compromise the system.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper input validation and sanitization mechanisms in the FestOS application. Additionally, file uploads should be restricted to specific directories and file types. Regular security updates and patches should be applied.