Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://fortiguard.com/advisory/FG-IR-16-080 | vendor advisory |
http://www.securityfocus.com/bid/96159 | vdb entry |