Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an executable or .bat file that can be executed with the help of a functionality (E.g. the "Application Starter" module) within the application.
References
Configurations
History
No history.
Information
Published : 2020-09-22 18:15
Updated : 2024-02-04 21:23
NVD link : CVE-2020-14022
Mitre link : CVE-2020-14022
CVE.ORG link : CVE-2020-14022
JSON object : View
Products Affected
ozeki
- ozeki_ng_sms_gateway
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type