Arbitrary file upload in SPPA-T3000 Application Server - CVE-2019-18288
Published: December 19, 2019
SPPA-T3000 Application Server
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file uploads. A remote authenticated attacker can upload and execute arbitrary file on the target system.
Note: an attacker needs to have access to the Application Highway in order to exploit this vulnerability.