PT-2019-18692 · Prima Systems · Flexair

Published

2019-07-01

·

Updated

2022-10-21

·

CVE-2019-7669

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Prima Systems FlexAir versions 2.3.38 and prior
Description The issue is related to improper validation of file extensions when uploading files. This could allow a remote authenticated attacker to upload and execute malicious applications within the application's web root with root privileges.
Recommendations For versions 2.3.38 and prior, update to a version that fixes the improper validation of file extensions to prevent malicious file uploads.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2019-7669

Affected Products

Flexair