In Keysight Geolocation Server v2.4.2 and prior,...
High severity
Unreviewed
Published
Jul 20, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jul 19, 2023
Published to the GitHub Advisory Database
Jul 20, 2023
Last updated
Apr 4, 2024
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.
References