CVE-2020-5846: Malicious File Upload

Published Jan 6, 2020
·
Updated

An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full system access as the configured user (e.g., Administrator) when starting from any authenticated session (e.g., a trial account). This is fixed in the 83/830122/cbs--hotfix-task26000 builds.

Affected Software

1 affected component
Ahsay Cloud Backup Suite=8.3.0.30

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Ahsay Cloud Backup Suite to a version that resolves this vulnerability.

    Fixed in 8.3.0.30Patch 83/830122/cbs-*-hotfix-task26000

Event History

Jan 6, 2020
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2020-5846?

CVE-2020-5846 has a severity score of 8.8, indicating a high level of risk.

2

How do I fix CVE-2020-5846?

To fix CVE-2020-5846, update Ahsay Cloud Backup Suite to the latest version that addresses this insecure file upload vulnerability.

3

What does CVE-2020-5846 exploit?

CVE-2020-5846 exploits an insecure file upload and allows for code execution via specific HTTP requests.

4

Which versions of Ahsay Cloud Backup Suite are affected by CVE-2020-5846?

CVE-2020-5846 specifically affects Ahsay Cloud Backup Suite version 8.3.0.30.

5

What is the impact of CVE-2020-5846?

The impact of CVE-2020-5846 includes the potential for unauthorized file uploads and remote code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203