Rule Name:CNVD-2017-20077: Ueditor .net Version Arbitrary File Upload Vulnerability
Severity:high
CVE ID:
Descripiton:
Ueditor is a WYSIWYG rich text web editor developed by Baidu web front-end R&D department. It is lightweight, customizable, and focused on user experience. The Ueditor .net version has arbitrary file upload vulnerabilities. Attackers can carefully construct the environment to upload files and obtain server management permissions. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None