KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://kujirahand.com/konawiki/ | vendor advisory |
https://jvn.jp/en/jp/JVN34232719/index.html | third party advisory |