Vulnerabilities > Ahsay > Cloud Backup Suite > 8.3.0.30

DATE CVE VULNERABILITY TITLE RISK
2020-01-06 CVE-2020-5846 Unrestricted Upload of File with Dangerous Type vulnerability in Ahsay Cloud Backup Suite 8.3.0.30
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body.
network
low complexity
ahsay CWE-434
4.0