vendor:
CLR-M20
by:
Safak Aslan
8.8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: CLR-M20
Affected Version From: 2.7.1.6
Affected Version To: 2.7.1.6
Patch Exists: No
Related CWE: 2018-15137
CPE: a:celalink:clr-m20:2.7.1.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
Cela Link CLR-M20 2.7.1.6 – Arbitrary File Upload
Due to the Via WebDAV (Web Distributed Authoring and Versioning), on the remote server, Cela Link CLR-M20 allows unauthorized users to upload any file(e.g. asp, aspx, cfm, html, jhtml, jsp, shtml) which causes remote code execution as well. Due to the WebDAV, it is possible to upload the arbitrary file utilizing the PUT method.
Mitigation:
Disable WebDAV on the server, or restrict access to the WebDAV directory.