First published: Thu Nov 29 2018(Updated: )
Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafted HTTP requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ocsinventory-ng ocsinventory NG |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15537 has a high severity rating due to its potential for remote code execution.
To fix CVE-2018-15537, ensure that file upload handling is properly validated and restricted within OCS Inventory NG.
CVE-2018-15537 allows for unrestricted file uploads that can lead to remote code execution.
Privileged users of OCS Inventory NG ocsreports are the primary individuals affected by CVE-2018-15537.
OCS Inventory NG, particularly versions prior to the patch for CVE-2018-15537, are impacted by this vulnerability.