vendor:
eMerge E3
by:
LiquidWorm
10.0
CVSS
CRITICAL
Arbitrary File Upload
434
CWE
Product Name: eMerge E3
Affected Version From: 1.00-06
Affected Version To: 1.00-06
Patch Exists: YES
Related CWE: CVE-2019-7257
CPE: a:linear_solutions:emerge_e3:1.00-06
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: NA
2018
eMerge E3 1.00-06 – Arbitrary File Upload
An arbitrary file upload vulnerability exists in eMerge E3 1.00-06. An attacker can exploit this vulnerability to upload a malicious file and execute arbitrary code on the server. This vulnerability is due to insufficient validation of the file type when uploading a file. An attacker can exploit this vulnerability by sending a malicious file with a double extension such as .php.jpg. This will bypass the validation and allow the attacker to upload the malicious file.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of the software.