Improper access control in SG Optimizer - #VU18080
Published: March 25, 2019 / Updated: March 26, 2019
SG Optimizer
Detailed vulnerability description
The vulnerability allows a remote attacker to upload arbitrary file to the server.
The vulnerability exists due to incorrect implementation of access permissions within the RESTFull API callback. A remote attacker can upload and execute arbitrary .php file on the system.
Successful exploitation of the vulnerability will result in system compromise.