First published: Mon Apr 27 2020(Updated: )
In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenance Mode setting.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rukovoditel Rukovoditel | =2.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11817 is a vulnerability in Rukovoditel V2.5.2 that allows attackers to upload an arbitrary file to the server and execute commands.
An attacker can exploit CVE-2020-11817 by changing the content-type value and uploading a file to execute commands on the server.
Rukovoditel V2.5.2 is the affected version of the software.
CVE-2020-11817 has a severity of critical with a CVSS score of 9.8.
To fix the vulnerability in Rukovoditel V2.5.2, you should update the software to a version that has addressed the issue. Follow the official documentation or contact the vendor for the latest patches or updates.