← Retour à la recherche de CVE

CVE-2026-80050

ContiNew Admin

Description

ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage backend accessible via web server URLs.

CVSS 6.5EPSS 0.247%Risque 0.66
Voir la source
Publication
2026-08-25 19:16:55
Versions concernées
unknown
Type
Application web
Dernière modification
2026-08-26 14:17:16
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N