What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in pathomation Pathomation pathomation allows Upload a Web Shell to a Web Server.This issue affects Pathomation: from n/a through <= 2.5.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in pathomation Pathomation pathomation allows Upload a Web Shell to a Web Server.This issue affects Pathomation: from n/a through <= 2.5.1.
Explanation of Vulnerability in Simple Terms
Pathomation versions up to 2.5.1 allow unauthenticated attackers to upload files without restriction. An attacker can upload malicious files over the network with no authentication or user interaction required. This can lead to remote code execution, data theft, or site takeover depending on where uploaded files are stored and executed.
What an attacker can do
Upload arbitrary files to the server without authentication, potentially leading to code execution or data compromise.
Potential impact on your site
An attacker can upload and execute malicious code on your site, steal data, or take full control without needing a user account.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities