NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an malicious user to obtain access to the operating system where NeDi is installed and to all application data.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
nedi nedi 1.9c |