Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
File upload and overwrite to app_data/Config in SmarterTrack v100.0.8019.14010
Vulnerability Description
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
SmarterTools SmarterTrack 代码问题漏洞
Vulnerability Description
SmarterTools SmarterTrack是英国SmarterTools公司的一款客户服务软件。可改善客户服务并降低支持成本。 SmarterTools SmarterTrack 100.0.8019.14010 存在安全漏洞,使用管理员或管理员权限的应用程序可能会被欺骗覆盖 app_data/Config 文件夹中的文件,例如 systemsettings.xml 文件。
CVSS Information
N/A
Vulnerability Type
N/A