CVE-2021-23280

CVE-2021-23280

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.

Source: CVE-2021-23280

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다