Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.
Solution:
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.incibe-cert.es/en/early-warning/security-advisories/integria-ims-remote-code-execution | third party advisory |
https://integriaims.com/en/services/updates/ | release notes vendor advisory |