ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-19384 | ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly. |
Fixes
Solution
Contact tech support from ARTWARE.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4850-9b53f-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T04:29:22.982Z
Reserved: 2021-05-10T00:00:00
Link: CVE-2021-32538
No data.
Status : Modified
Published: 2021-07-07T14:15:12.237
Modified: 2024-11-21T06:07:13.530
Link: CVE-2021-32538
No data.
OpenCVE Enrichment
No data.
EUVD