PT-2026-49106 · Unknown · Iptanus File Upload
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Iptanus File Upload versions prior to 5.1.7
Description
Improper file handling occurs when the
duplicatepolicy setting is configured to "maintain both." A Time-of-Check to Time-of-Use (TOCTOU) race condition—a scenario where a system checks a condition (such as file existence) but the state changes before the resulting action (writing the file) is performed—exists between the file existence check and the actual file write operation. This allows an authenticated attacker to overwrite files uploaded by other users.Recommendations
Update to version 5.1.7 or later.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iptanus File Upload