Arbitrary Code Execution via Insufficient Verification of Uploaded WebUI Themes

Arbitrary Code Execution via Insufficient Verification of Uploaded WebUI Themes

CVE-2016-8494 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.

Learn more about our Web App Pen Testing.