CVE-2020-26804 Information
Feb 14, 2021
cve
Description
In Sentrifugo 3.2 users can share an announcement under \Organization - Announcements\ tab. Also in this page users can upload attachments with the shared announcements. This \Upload Attachment\ functionality is suffered from \Unrestricted File Upload\ vulnerability so attacker can upload malicious files using this functionality and control the server.
Reference
https://fatihhcelik.blogspot.com/2020/10/sentrifugo-version-32-rce-authenticated.html
Share on: