CVE-2018-15537: Malicious File Upload
Published Nov 29, 2018
·Updated
Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafted HTTP requests.
Affected Software
1 affected component
Ocsinventory-ng Ocsinventory Ng
Event History
Nov 29, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-15537?
CVE-2018-15537 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2018-15537?
To fix CVE-2018-15537, ensure that file upload handling is properly validated and restricted within OCS Inventory NG.
3
What type of attack does CVE-2018-15537 allow?
CVE-2018-15537 allows for unrestricted file uploads that can lead to remote code execution.
4
Who is affected by CVE-2018-15537?
Privileged users of OCS Inventory NG ocsreports are the primary individuals affected by CVE-2018-15537.
5
What software versions are impacted by CVE-2018-15537?
OCS Inventory NG, particularly versions prior to the patch for CVE-2018-15537, are impacted by this vulnerability.