CVE-2022-34919

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
23/08/2022
Last modified:
25/08/2022

Description

The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zengenti:contensis:*:*:*:*:classic:*:*:* 15.2.1.79 (excluding)