Unauthenticated File Upload Vulnerability in Digiwin ERP 5.1 with Remote Code Execution
A critical vulnerability exists in Digiwin ERP 5.1 within the /Api/FileUploadApi.ashx file. The DoUpload/DoWebUpload function has an unrestricted file upload flaw through manipulation of the File argument. This vulnerability can be triggered remotely, allowing attackers to upload files without proper restrictions. The issue has been publicly disclosed, and the potential for exploitation is high. Despite early notification, the vendor did not provide a response to address the security problem.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
digiwin erp |