What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
Explanation of Vulnerability in Simple Terms
Tribulant Newsletters versions up to 4.9.5 allow authenticated administrators to upload files without proper validation. An attacker with admin privileges can upload malicious files to compromise the site. The vulnerability affects file handling across the application, potentially allowing code execution or data manipulation.
What an attacker can do
Upload malicious files to the site and execute code or modify data.
Potential impact on your site
A compromised admin account can be used to upload files that take over your site or steal data.
Conditions required to exploit
Attacker must have administrator-level access to the site.
Key dates
External resources
Related vulnerabilities