PT-2026-52989 · Dmp-5000 · Dmp-5000
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DMP-5000 (affected versions not specified)
Description
The file service allows authenticated users to upload files of any type without validation. The system does not enforce file extension filtering or content inspection, which enables the upload of executable binaries and scripts directly to the server.
Recommendations
Restrict file upload permissions immediately.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dmp-5000