#VU27525 Permissions, Privileges, and Access Controls in MonoX - CVE-2020-12470
Published: May 5, 2020
MonoX
Mono
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in the "ctlUpload_radUploadfile0" parameter in "MonoX.MonoSoftware.MonoX.Admin.PageManagerPageTemplates" file. A remote administrator can modify ASPX templates for the entire site, gain elevated privileges and execute arbitrary code.