CVE-2022-27249
03.04.2022, 23:15
An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted aspx file to the web root, and then visiting the URL for this aspx resource.Enginsight
Vendor | Product | Version |
---|---|---|
idearespa | reftree | 𝑥 < 2021.09.17 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration