CyberRota Analysis
AI-GeneratedThe vulnerability arises from improper sanitization of filenames during file uploads, enabling attackers to inject shell metacharacters and execute arbitrary commands on the system. This critical flaw poses a significant risk to any application utilizing the affected file upload functionality, potentially leading to unauthorized access or system compromise. Organizations that implement file upload features should prioritize immediate remediation to mitigate the risk of exploitation.
Original NVD Description
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
Related CVEs
Other vulnerabilities affecting the same vendor(s)