An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted aspx file to the web root, and then visiting the URL for this aspx resource.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/166559/IdeaRE-RefTree-Shell-Upload.html | Exploit Third Party Advisory VDB Entry |
https://www.idearespa.eu | Product |
http://packetstormsecurity.com/files/166559/IdeaRE-RefTree-Shell-Upload.html | Exploit Third Party Advisory VDB Entry |
https://www.idearespa.eu | Product |
Configurations
History
No history.
Information
Published : 2022-04-03 23:15
Updated : 2024-11-21 06:55
NVD link : CVE-2022-27249
Mitre link : CVE-2022-27249
CVE.ORG link : CVE-2022-27249
JSON object : View
Products Affected
idearespa
- reftree
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type