vendor:
Zazavi
by:
KedAns-Dz
7.5
CVSS
HIGH
Arbitrary File Upload
CWE
Product Name: Zazavi
Affected Version From: 1.2.2001
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Zazavi Arbitrary File Upload Vulnerability
Zazavi is prone to an arbitrary-file-upload vulnerability because the application fails to adequately sanitize user-supplied input. An attacker can exploit this issue to upload arbitrary code and run it in the context of the webserver process.
Mitigation:
Implement proper input validation and sanitization to prevent arbitrary file uploads.