The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter.
References
| Link | Resource |
|---|---|
| https://energy-log-server-6x.readthedocs.io/en/latest/CHANGELOG.html | Release Notes Third Party Advisory |
| https://github.com/emca-it/Energy-Log-Server-6.x/commits/master | Patch Third Party Advisory |
| https://energylogserver.pl/en/ | Vendor Advisory |
| https://gist.github.com/ahpaleus/effb46d4a9d9c2b9a452c98f64ddc2c7 | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-08-05 05:15
Updated : 2019-08-13 06:46
NVD link : CVE-2019-14521
Mitre link : CVE-2019-14521
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
emca
- energy_logserver


