Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://huntr.dev/bounties/a0e5c68e-0f75-499b-bd7b-d935fb8c0cd1 | exploit third party advisory patch |
https://github.com/inventree/inventree/commit/26bf51c20a1c9b3130ac5dd2e17649bece5ff84f | third party advisory patch |