File Upload Vulnerability in Rukovoditel by Rukovoditel
CVE-2020-11817

9.8CRITICAL

Key Information:

Vendor
CVE Published:
27 April 2020

What is CVE-2020-11817?

In Rukovoditel V2.5.2, attackers can exploit a flaw that allows for the upload of arbitrary files to the server by simply altering the content-type header. This vulnerability, which occurs while the Maintenance Mode is active, can enable malicious actors to execute commands on the server, potentially compromising sensitive information and server integrity.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.