CVE Published: 27/08/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: tenable |
Vendor: Tenable |
Product: ASUSTOR Data Master Status : PUBLISHED
CVE-2018-15694 Description
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.