cve/2024/CVE-2024-25153.md
2024-05-25 21:48:12 +02:00

1.2 KiB
Raw Blame History

CVE-2024-25153

Description

A directory traversal within the ftpservlet of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended uploadtemp directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portals DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.

POC

Reference

No PoCs from references.

Github