Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://extensis.com | product |
http://portfolio.com | not applicable |
https://www.whiteoaksecurity.com/blog/extensis-portfolio-vulnerability-disclosure/ | third party advisory exploit |