801
VMScore

CVE-2022-27249

Published: 03/04/2022 Updated: 09/04/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An unrestricted file upload vulnerability in IdeaRE RefTree prior to 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted aspx file to the web root, and then visiting the URL for this aspx resource.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

idearespa reftree

Exploits

IdeaRE RefTree versions prior to 20210917 suffer from a remote shell upload vulnerability ...