A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://vuldb.com/?id.319375 | technical description vdb entry |
https://vuldb.com/?ctiid.319375 | signature permissions required |
https://vuldb.com/?submit.623100 | third party advisory |
https://github.com/zlt2000/microservices-platform/issues/77 | issue tracking |
https://github.com/zlt2000/microservices-platform/issues/77#issue-3264841808 | issue tracking exploit |