CVE-2022-42971 Information
Feb 02, 2023
cve
Description
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7 10 11 & Windows Server 2016 2019 2022 - Versions prior to V2.5-GA) APC Easy UPS Online Monitoring Software (Windows 11 Windows Server 2019 2022 - Versions prior to V2.5-GA-01-22261) Schneider Electric Easy UPS Online Monitoring Software (Windows 7 10 11 & Windows Server 2016 2019 2022 - Versions prior to V2.5-GS) Schneider Electric Easy UPS Online Monitoring Software (Windows 11 Windows Server 2019 2022 - Versions prior to V2.5-GS-01-22261)