An issue was discovered in Ovidentia 8.3. The file upload...
Critical severity
Unreviewed
Published
Jan 7, 2025
to the GitHub Advisory Database
•
Updated Jan 8, 2025
Description
Published by the National Vulnerability Database
Jan 7, 2025
Published to the GitHub Advisory Database
Jan 7, 2025
Last updated
Jan 8, 2025
An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/common/ URI for remote code execution.
References