Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://pitstop.manageengine.com/portal/kb/articles/latest-consolidated-patch | patch vendor advisory |
https://blogs.securiteam.com/index.php/archives/3228 | exploit third party advisory patch |