PT-2022-10755 · Softvibe · Softvibe Saraban For Infoma

Published

2022-01-18

·

Updated

2024-02-14

·

CVE-2021-38697

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SoftVibe SARABAN for INFOMA version 1.1
Description The issue allows unauthenticated unrestricted file upload, enabling attackers to upload files with any file extension, which can lead to arbitrary code execution.
Recommendations For SoftVibe SARABAN for INFOMA version 1.1, consider restricting file upload capabilities to authenticated users and validating file extensions to prevent malicious uploads until a patch is available. As a temporary workaround, restrict access to the file upload feature to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2021-38697

Affected Products

Softvibe Saraban For Infoma