vendor:
Prima Access Control
by:
LiquidWorm
8.8
CVSS
HIGH
Arbitrary File Upload
CWE
Product Name: Prima Access Control
Affected Version From: 2.3.35
Affected Version To: 2.3.35
Patch Exists: NO
Related CWE: CVE-2019-9189
CPE:
Platforms Tested:
2019
Prima Access Control 2.3.35 – Arbitrary File Upload
This exploit allows an attacker to upload arbitrary files to the Prima Access Control software version 2.3.35. By sending a specially crafted POST request to the sysfcgi.fx endpoint, an attacker can upload a malicious Python script that can execute arbitrary commands on the target system.
Mitigation:
Update to a patched version of the software.