The file upload function of Agentflow BPM has...
Critical severity
Unreviewed
Published
Nov 10, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Nov 10, 2022
Published to the GitHub Advisory Database
Nov 10, 2022
Last updated
Jan 27, 2023
The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary file and execute arbitrary code to manipulate system or disrupt service.
References