Required CVE Record Information
Description
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- https://github.com/erberkan/SonLogger-vulns x_transferred
- https://www.sonlogger.com/releasenotes x_transferred
- http://packetstormsecurity.com/files/161793/SonLogger-4.2.3.3-Shell-Upload.html x_transferred