An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.
This Cyber News was published on www.tenable.com. Publication date: Thu, 11 Apr 2024 22:56:03 +0000