An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/h4ckr4v3n/research_redaxo_5_17_1.git | third party advisory |
https://gist.github.com/h4ckr4v3n/26eaa57d94f749b597ede8b404c234df | third party advisory |