Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.
References
Link | Resource |
---|---|
https://www.monstaftp.com/notes/ | Release Notes Vendor Advisory |
https://github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20191203-01_Monsta_FTP_Arbitrary_File_Read_and_Write | Third Party Advisory |
Configurations
Information
Published : 2020-07-01 10:15
Updated : 2020-07-08 06:18
NVD link : CVE-2020-14057
Mitre link : CVE-2020-14057
JSON object : View
CWE
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
Products Affected
monstaftp
- monsta_ftp