CVE-2020-14022
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
22/09/2020
Last modified:
26/09/2020
Description
Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an executable or .bat file that can be executed with the help of a functionality (E.g. the "Application Starter" module) within the application.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ozeki:ozeki_ng_sms_gateway:*:*:*:*:*:*:*:* | 4.17.6 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-14022-Dangerous%20File%20Upload-Ozeki%20SMS%20Gateway
- https://www.ozeki.hu/index.php?ow_page_number=1017&downloadaction=email&download_product_id=1&os=windows&dpath=/attachments/702/installwindows_1590575794_OzekiNG-SMS-Gateway_4.17.6.zip&dname=Ozeki%20NG%20SMS%20Gateway%20v4.17.6&dsize=%20%2817.8%20MB%29&platform=Windows
- https://www.ozeki.hu/index.php?owpn=231



