Improper access control in Adning Advertising - #VU29575
Published: July 7, 2020
Adning Advertising
tunafish
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in AJAX API. A remote attacker can bypass implemented security restrictions and upload/delete arbitrary files on the target system.
Note: The vulnerability is being actively exploited in the wild.