#VU52039 Arbitrary file upload in SonicWall On-premise Email Security (ES) and SonicWall Hosted Email Security (HES) - CVE-2021-20022
Published: April 12, 2021 / Updated: April 21, 2021
SonicWall On-premise Email Security (ES)
SonicWall Hosted Email Security (HES)
SonicWall
Description
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload within the branding feature. A remote administrator can upload a malicious ZIP archive to the system to an arbitrary location using directory traversal sequences in the filenames inside the uploaded archive and compromise the affected system.
Note, the vulnerability is being actively exploited in the wild.