PT-2026-28717 · Unknown · Z-9527 Admin
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
z-9527 admin versions prior to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2
Description
A security issue has been identified in z-9527 admin. The issue resides within the
uploadFile function located in the /server/utils/upload.js file, specifically within the isImg Check component. Manipulation of the fileType argument can lead to a path traversal condition. Remote exploitation is possible. The exploit has been publicly disclosed.Recommendations
Update z-9527 admin to version 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2 or later.
As a temporary workaround, restrict access to the
uploadFile function in the /server/utils/upload.js file.
Avoid using the fileType parameter in the uploadFile function until the issue is resolved.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Z-9527 Admin