The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://leaftecnologia.com.br/ | vendor advisory |
http://intruderlabs.com.br/ | not applicable |
https://gist.github.com/alacerda/8fd4557e585a8707e9d3b798968e24c1 | third party advisory |