CyberRota Analysis
AI-GeneratedThe Flowring Agentflow 4.0 version prior to March 24, 2023, is vulnerable due to an unrestricted file upload feature in the /WebAgenda/download/uploadFile.jsp API endpoint, allowing remote authenticated users to upload malicious files. This flaw can lead to arbitrary command execution on the server, posing a critical risk to system integrity and confidentiality. Organizations using this software should prioritize immediate remediation to mitigate potential exploitation.
Original NVD Description
Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file.