vendor:
atrocore
by:
nu11secur1ty
9
CVSS
CRITICAL
User interaction - Unauthenticated File upload - RCE
CWE
Product Name: atrocore
Affected Version From: 1.5.25
Affected Version To: 1.5.25
Patch Exists:
Related CWE:
CPE:
Platforms Tested:
2023
atrocore 1.5.25 User interaction – Unauthenticated File upload – RCE
The `Create Import Feed` option with `glyphicon-glyphicon-paperclip` function appears to be vulnerable to User interaction - Unauthenticated File upload - RCE attacks. The attacker can easily upload a malicious then can execute the file and can get VERY sensitive information about the configuration of this system, after this he can perform a very nasty attack.