The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Team+_pro | Teamplus | 13.5.0 (including) | 14.0.0 (excluding) |