Loading vulnerability details…
CVSS v3.1
N/A
EPSS
75.17%
Published
Jul 26, 2019
Modified
Nov 21, 2024
Public PoC / Exploit (3)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the system, as the configured user (e.g., Administrator).
Weaknesses (CWE)
Affected Products (1)
References (6)