A issue was discovered in SiteServer CMS prior to version 6.12. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp
, which is converted to .asp
because the "as" substring is deleted.
{ "nvd_published_at": "2019-04-22T11:29:00Z", "cwe_ids": [ "CWE-434" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-14T20:14:41Z" }