PT-2019-14929 · Footy Tipping · Footy Tipping Software Afl Web Edition
Published
2019-11-18
·
Updated
2019-11-20
·
CVE-2019-17058
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Footy Tipping Software AFL Web Edition version 2019
Description
The issue allows for arbitrary file upload and resultant remote code execution. This is possible because a whitelist can be bypassed by an Administrator who uploads a crafted
upload.dat file.Recommendations
For Footy Tipping Software AFL Web Edition version 2019, consider restricting access to the file upload functionality for Administrators until a patch is available. As a temporary workaround, monitor the upload directory for suspicious files, especially crafted
upload.dat files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Footy Tipping Software Afl Web Edition