A remote code execution vulnerability was identified in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can invoke code execution upon uploading a carefully crafted JPEG file as part of the profile avatar.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/158434/SecZetta-NEProfile-3.3.11-Remote-Code-Execution.html | Third Party Advisory VDB Entry |
https://seczetta.com | Vendor Advisory |
Configurations
Information
Published : 2020-07-15 13:15
Updated : 2020-07-22 10:12
NVD link : CVE-2020-12854
Mitre link : CVE-2020-12854
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
seczetta
- neprofile