SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.
References
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2021-02-24 12:15
Updated : 2021-03-01 16:09
NVD link : CVE-2021-20659
Mitre link : CVE-2021-20659
CVE.ORG link : CVE-2021-20659
JSON object : View
Products Affected
contec
- sv-cpt-mc310_firmware
- sv-cpt-mc310
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type