An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCipplanner Cipace
APPCipplanner< 9.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2020-11597CRITICAL9.8PL ✓same product
SQL Injection bez uwierzytelnienia w CIPPlanner CIPAce 9.1
CVE-2020-11586CRITICAL9.8PL ✓same product
XXE w CIPPlanner CIPAce — nieautoryzowany dostęp przez złośliwe DTD
CVE-2024-50619HIGH8.8same product
Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attac...
CVE-2024-50617HIGH7.5same product
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow at...
CVE-2024-50620HIGH8.8same product
Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document man...