CVE-2019-12271

Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.
References
Link Resource
https://link.medium.com/Y2S4ZJbMy1 Exploit Third Party Advisory
http://packetstormsecurity.com/files/155355/Centraleyezer-Shell-Upload.html Third Party Advisory VDB Entry
Configurations

Configuration 1

cpe:2.3:a:sandline:centraleyezer:-:*:*:*:on_premise:*:*:*

Information

Published : 2019-11-18 07:15

Updated : 2019-11-21 02:43


NVD link : CVE-2019-12271

Mitre link : CVE-2019-12271

Products Affected
No products.
CWE