Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
The vulnerability results from a lack of proper validation of uploaded files (CWE-434 — unrestricted file upload) and the possibility of system command injection (CWE-78) or malicious code execution (CWE-94). An authenticated attacker uploads a specially crafted file to the server and then causes it to be executed by the application, resulting in arbitrary code execution in the server context.
An attacker can gain full control of the server, including reading and modifying data, installing additional software (e.g., backdoor), and potentially moving laterally across the internal network (lateral movement).
Apply patches available from the vendor according to the references: https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26. Additionally, it is recommended to restrict access to the file upload interface to trusted users only and monitor server activity for suspicious operations.
Progress Sharefile Storage Zones Controller — versions indicated in the vendor references (https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HProgress Sharefile Storage Zones Controller
APPProgress5.0.0 – 5.12.4 (excl.)
Related vulnerabilities
Auth Bypass i RCE w Progress ShareFile Storage Zones Controller
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perf...
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted...
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administ...
Path traversal w Progress ShareFile Storage Zones Controller