CVE-2019-14521 Information
Feb 14, 2021
cve
Description
The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Reference
https://energylogserver.pl/en/ https://energy-log-server-6x.readthedocs.io/en/latest/CHANGELOG.html https://gist.github.com/ahpaleus/effb46d4a9d9c2b9a452c98f64ddc2c7 https://github.com/emca-it/Energy-Log-Server-6.x/commits/master
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
7.5
Share on: