Improper access control in SnapCreek Duplicator - #VU14790
Published: September 17, 2018
SnapCreek Duplicator
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary PHP code on the target system.
The vulnerability exists due to the web application does not restrict access to the installation script "/installer-backup.php" or "/installer.php" script. A remote unauthenticated attacker can upload malicious file via HTTP POST request and execute arbitrary PHP code on the target system.