SQL injection and file upload attacks are possible due to...
Critical severity
Unreviewed
Published
Jun 3, 2022
to the GitHub Advisory Database
•
Updated Jul 4, 2023
Description
Published by the National Vulnerability Database
Jun 2, 2022
Published to the GitHub Advisory Database
Jun 3, 2022
Last updated
Jul 4, 2023
SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulnerabilities to perform attacks such as stealing server management rights using a web shell.
References