vendor:
Kartris
by:
Nhat Ha - Sun CSR
9.8
CVSS
CRITICAL
Arbitrary File Upload
CWE
Product Name: Kartris
Affected Version From: 1.6
Affected Version To: 1.6
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: WiN10_x64/KaLiLinuX_x64
2020
Kartris 1.6 – Arbitrary File Upload
The Kartris version 1.6 allows an attacker to upload arbitrary files via the _GeneralFiles.aspx page. This can lead to remote code execution and unauthorized access to sensitive information.
Mitigation:
Update to the latest version of Kartris and ensure proper file upload validation is implemented.