PT-2022-16565 · Extensis · Extensis Portfolio

Published

2022-03-01

·

Updated

2022-03-09

·

CVE-2022-24252

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Extensis Portfolio version 4.0
Description The issue is related to an unrestricted file upload vulnerability in the FileTransferServlet component, allowing remote attackers to execute arbitrary code via a crafted file.
Recommendations For Extensis Portfolio version 4.0, consider restricting access to the FileTransferServlet component until a patch is available. As a temporary workaround, avoid using the FileTransferServlet component to upload files from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24252

Affected Products

Extensis Portfolio