云虫漏洞库

CVE-2026-16137 - In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code. - 漏洞详情

漏洞编号:CVE-2026-16137

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-16137

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-22

发布/更新时间:2026-08-17 / 2026-08-28

漏洞描述

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.

相关链接

相关漏洞

« 返回首页