An issue was discovered in BACKCLICK Professional 5.9.63....
Critical severity
Unreviewed
Published
Nov 17, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Nov 16, 2022
Published to the GitHub Advisory Database
Nov 17, 2022
Last updated
Jan 31, 2023
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.
References