What the vulnerability does
01Description
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
Explanation of Vulnerability in Simple Terms
Mailster versions up to 4.1.17 allow authenticated administrators to upload files without proper validation. An attacker with admin privileges can upload malicious files that may compromise the site's integrity and availability. The vulnerability affects the entire system due to scope change. Update to a version newer than 4.1.17.
What an attacker can do
Upload malicious files to the site and execute code or disrupt operations.
Potential impact on your site
An admin account compromise could lead to full site takeover, data theft, or service disruption.
Conditions required to exploit
Attacker must have administrator-level access to Mailster.
Key dates
External resources
Related vulnerabilities