The “restore configuration” feature of Softing Secure...
High severity
Unreviewed
Published
Aug 18, 2022
to the GitHub Advisory Database
•
Updated Jun 27, 2023
Description
Published by the National Vulnerability Database
Aug 17, 2022
Published to the GitHub Advisory Database
Aug 18, 2022
Last updated
Jun 27, 2023
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path traversal file may cause a file to be created and executed upon touching the disk.
References