Skip to content

Unrestricted Upload of File with Dangerous Type

High
MaKyOtOx published GHSA-5hc9-6hq4-2xfx Dec 14, 2021

Package

No package listed

Affected versions

<1.7.7

Patched versions

1.7.7

Description

Impact

PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server.

Patches

Update to 1.7.7

Workarounds

Not known

References

Huntr.dev Bug Report by M0rphling

Severity

High

CVE ID

CVE-2021-43829

Weaknesses

Credits