CVE-2017-14123: Malicious File Upload
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14123?
CVE-2017-14123 is classified as a high severity vulnerability due to its ability to allow arbitrary file uploads.
How do I fix CVE-2017-14123?
To mitigate CVE-2017-14123, ensure that you apply the latest patches provided by Zoho for ManageEngine Firewall Analyzer.
What are the potential impacts of CVE-2017-14123?
The potential impacts of CVE-2017-14123 include remote code execution and complete control over the affected server.
Who is affected by CVE-2017-14123?
CVE-2017-14123 affects users of Zoho ManageEngine Firewall Analyzer version 12.2-12200.
What is the nature of the vulnerability in CVE-2017-14123?
CVE-2017-14123 is an unrestricted file upload vulnerability that allows users to upload PHP files, leading to possible code execution.