Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application’s web root with root privileges.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://applied-risk.com/labs/advisories | third party advisory |
https://www.applied-risk.com/resources/ar-2019-007 | third party advisory |
https://www.us-cert.gov/ics/advisories/icsa-19-211-02 | third party advisory us government resource |
http://packetstormsecurity.com/files/155270/FlexAir-Access-Control-2.3.38-Command-Injection.html | exploit vdb entry third party advisory |