ZeroHour

CVE-2017-14771

CVSS 3.0
5.5 medium
EPSS
<1%p21
Published
()
Modified
Description

Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application. During a debugger-pause state, a local authenticated attacker can upload an arbitrary file and overwrite existing files within the scope of the affected application.

Vendors
skyboxsecurity
Products
skybox manager client application
Weakness
CWE-20
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.