Ssh Company · Cckevincyh Ssh Companywebsite · CVE-2018-14441
**Name of the Vulnerable Software and Affected Versions**
cckevincyh SSH CompanyWebsite through 2018-05-03
**Description**
An issue was discovered that allows arbitrary file upload. This is demonstrated by uploading a .jsp file with the `content type` set to `image/jpeg`. The upload is possible through the "admin/admin/fileUploadAction fileUpload.action" endpoint.
**Recommendations**
For versions through 2018-05-03, consider restricting access to the "fileUploadAction fileUpload.action" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the file upload feature until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.