Description
|
|
Two vulnerabilities have been identified in Achievo, which could be exploited by malicious users to gain knowledge of sensitive information or compromise a vulnerable system.
The first issue is caused by an error in the docmanager that does not validate file extensions when uploading files, which could allow malicious users to upload PHP scripts and execute arbitrary code with the privileges of the web server.
The second vulnerability is caused by an input validation error in the scheduler when processing user-supplied data, which could be exploited by malicious users to conduct cross site scripting attacks.
|