A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://vtenext.com/en/ | vendor advisory |
https://sourceforge.net/projects/vtecrm/ | third party advisory product |
https://www.exploit-db.com/exploits/48804 | vdb entry third party advisory |