CVE-2023-29770
EUVD-2023-3330828.11.2023, 00:15
In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension filtering.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sapplica | sentrifugo | 3.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration