The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Activepost_standard | Onnuri_infotek | * | 3.1 (including) |
Activepost_standard | Onnuri_infotek | 2.5 (including) | 2.5 (including) |
Activepost_standard | Onnuri_infotek | 3.0 (including) | 3.0 (including) |