The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter.
References
Link | Resource |
---|---|
https://energy-log-server-6x.readthedocs.io/en/latest/CHANGELOG.html | Release Notes Third Party Advisory |
https://energylogserver.pl/en/ | Vendor Advisory |
https://gist.github.com/ahpaleus/effb46d4a9d9c2b9a452c98f64ddc2c7 | Exploit Third Party Advisory |
https://github.com/emca-it/Energy-Log-Server-6.x/commits/master | Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-08-05 12:15
Updated : 2024-02-28 17:08
NVD link : CVE-2019-14521
Mitre link : CVE-2019-14521
CVE.ORG link : CVE-2019-14521
JSON object : View
Products Affected
emca
- energy_logserver
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')