An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.
This Cyber News was published on www.tenable.com. Publication date: Thu, 08 Feb 2024 06:41:03 +0000