ZZ_Resolve Unrestricted File Upload Vulnerability
Vulnerability
A critical vulnerability allowing arbitrary file upload has been identified in ZZ_Resolve versions through 2024-8. The issue arises in the '/resolve' endpoint, where improper handling of the 'file' argument permits unrestricted file uploads. This vulnerability can be exploited remotely.
Impact
Exploitation of this vulnerability allows for arbitrary file uploads, which could lead to further attacks such as remote code execution, depending on the uploaded file and the application's handling of it.
Reproduction
To reproduce this vulnerability, send a POST request to the '/resolve' endpoint with 'multipart/form-data' content. Include a file in the 'file' field, such as a JSP file, and add a 'filepath' field with the value '/'. The server will accept the uploaded file without proper validation.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
