External Control of File Name or Path in OAS Platform - CVE-2024-21870
Published: April 8, 2024
OAS Platform
Open Automation Software
Description
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to application allows an attacker to control path of the files within the OAS Engine Tags Configuration functionality. A remote administrator can send a specially crafted HTTP request and create or overwrite arbitrary files on the system.