[0day-rubbish] PrizmDoc for Java (VirtualViewer) 5.22.1 Unauthenticated uploadDocument write into the webapp root to JSP webshell (9.8)
Unauthenticated upload in PrizmDoc for Java 5.22.1 writes a JSP webshell into the webapp root as root.
0day Rubbish Research Team disclosed an unauthenticated file-upload flaw in PrizmDoc for Java (VirtualViewer) 5.22.1. The uploadDocument function writes into the web application root, allowing a JSP webshell (CWE-306) that executes with the JVM's privileges—uid 0 (root) in the deployment the researchers verified. CVSS is given as 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The post advertises a reproducible proof-of-concept and does not cite a CVE or confirmed exploitation.
- Affects PrizmDoc for Java (VirtualViewer) 5.22.1.
- Unauthenticated uploadDocument writes into the web application root.
- Result is a JSP webshell running with JVM privileges, uid 0 in the verified deployment.
- CVSS 9.8 with a claimed public PoC; no CVE or in-the-wild use stated.
Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in PrizmDoc for Java (VirtualViewer) 5.22.1. Type: Unauthenticated uploadDocument write into the webapp root to JSP webshell (CWE-306) CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Impact: JSP webshell execution with the JVM privileges, uid 0 (root) in the verified deployment Authentication: unauthenticated Full technical analysis and a reproducible proof-of-concept:...
This source does not provide full text. Read it at seclists.org.