QID 150581
Date Published: 2022-10-10
QID 150581: WSO2 File Upload Remote Command Execution Vulnerability (CVE-2022-29464)
WSO2 is an open-source technology. It offers an enterprise platform for integrating application programming interfaces, applications, and web services locally and across the Internet.
Due to improper validation of user input, a malicious actor could upload an arbitrary file to a user controlled location of the server. By leveraging the arbitrary file upload vulnerability, it is further possible to gain remote code execution on the server.
Affected Products:
WSO2 API Manager 2.2.0, up to 4.0.0
WSO2 Identity Server 5.2.0, up to 5.11.0
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks for vulnerable version of WSO2 running on the target application.
By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.
- WSO2-2021-1738 -
docs.wso2.com/pages/viewpage.action?pageId=180952746
CVEs related to QID 150581
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WSO2-2021-1738 |
|