File Upload Vulnerability in Nokia IMPACT IoT Platform
CVE-2021-35485
8HIGH
What is CVE-2021-35485?
An issue in the Applications component of the Nokia IMPACT IoT Platform allows authenticated users to upload server-side executable files through the /ui/rest-proxy/application fileupload parameter. This vulnerability can be exploited while adding or editing applications, potentially allowing unauthorized access and control over the server environment.