PT-2022-23365 · Rocket · Rocket Trufusion Enterprise
Published
2022-12-01
·
Updated
2025-04-24
·
CVE-2022-36431
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rocket TRUfusion Enterprise versions prior to 7.9.6.1
Description
The issue allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. This is due to an arbitrary file upload vulnerability.
Recommendations
For versions prior to 7.9.6.1, update to version 7.9.6.1 to resolve the issue. As a temporary workaround, consider restricting access to file upload functionality to minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocket Trufusion Enterprise