SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/erberkan/SonLogger-vulns | third party advisory exploit |
https://www.sonlogger.com/releasenotes | release notes vendor advisory |
http://packetstormsecurity.com/files/161793/SonLogger-4.2.3.3-Shell-Upload.html | exploit vdb entry third party advisory |