Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This issue affects MegaBIP software versions through 5.10.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://cert.pl/en/posts/2024/06/CVE-2024-1576/ | third party advisory |
https://cert.pl/posts/2024/06/CVE-2024-1576/ | third party advisory |
https://megabip.pl/ | product |
https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej | government resource press/media coverage |