Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application’s web root with root privileges.
References
Configurations
Information
Published : 2019-07-01 19:15
Updated : 2020-08-24 17:37
NVD link : CVE-2019-7669
Mitre link : CVE-2019-7669
JSON object : View
Products Affected
primasystems
- flexair
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
