eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/Chu1z1/Chuizi/issues/1 | issue tracking exploit third party advisory |