Security Advisory

CVE-2015-7904

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-10-28 10:00:00
Last updated 2024-08-06 08:06:30
Assigner icscert
CVSS score not scored
State PUBLISHED

Description

Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file.