CVE-2022-47878

Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jedox:jedox:2020.2.5:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-02 20:15

Updated : 2024-02-28 20:13


NVD link : CVE-2022-47878

Mitre link : CVE-2022-47878

CVE.ORG link : CVE-2022-47878


JSON object : View

Products Affected

jedox

  • jedox
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type