Description
The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general user can upload and execute arbitrary files, to manipulate system or disrupt service.
No analysis available yet.
Remediation
Vendor Solution
Update Easytest version to v.22I26
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-46439 | The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general user can upload and execute arbitrary files, to manipulate system or disrupt service. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-6828-1e5e4-1.html |
|
History
Thu, 10 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-04-10T16:47:43.259Z
Reserved: 2022-10-19T00:00:00.000Z
Link: CVE-2022-43436
Updated: 2024-08-03T13:32:58.703Z
Status : Modified
Published: 2023-01-03T03:15:10.107
Modified: 2024-11-21T07:26:28.980
Link: CVE-2022-43436
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD