Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-05-02T00:00:00

Updated: 2024-08-03T15:02:36.543Z

Reserved: 2022-12-21T00:00:00

Link: CVE-2022-47878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-05-02T20:15:10.647

Modified: 2023-05-10T14:10:16.187

Link: CVE-2022-47878

cve-icon Redhat

No data.