Description
A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When this is combined with CVE-2019-14451, an attacker can upload an "external command" configuration as a printer configuration, and achieve remote code execution. After exploitation, loading of the external command configuration is dependent on a system reboot or service restart.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T00:19:40.999Z
Reserved: 2019-07-30T00:00:00.000Z
Link: CVE-2019-14450
No data.
Status : Modified
Published: 2019-10-28T17:15:19.877
Modified: 2024-11-21T04:26:45.937
Link: CVE-2019-14450
No data.
OpenCVE Enrichment
No data.
Weaknesses