漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Upload restriction bypass in Wertheim SafeController Software allows authenticated users to upload arbitrary files
Vulnerability Description
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint. The application validates uploaded files based on the user-controlled HTTP Content-Type value and accepts the upload if this value contains an allowed string such as pdf, jpeg, tiff, or png. An authenticated attacker with any role or permission level can spoof the Content-Type value and upload arbitrary file content.
CVSS Information
N/A
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Wertheim SafeController Software for VAULT ROOMS 任意文件上传漏洞
Vulnerability Description
Wertheim SafeController Software for VAULT ROOMS是Wertheim公司的一款金库安全保险柜系统的控制软件。 Wertheim SafeController Software for VAULT ROOMS 6.15.8328.28014版本存在任意文件上传漏洞,该漏洞源于/safe/contract/uploadcustomdocuments端点对服务器端文件类型验证不足,攻击者可通过伪造Content-Type值上传任意文件。
CVSS Information
N/A
Vulnerability Type
N/A