Roncoo.Education.ApiUploadController.Arbitrary.File.Upload

description-logoDescription

This indicates an attack attempt against an Arbitrary File Upload vulnerability in Roncoo Education.
The vulnerability is due to improper user input validation when processing forms file uploads. A successful attack may result in upload of arbitrary files on the target server, which may lead to remote code execution.

affected-products-logoAffected Products

Roncoo Education v9.0.0

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://github.com/roncoo/roncoo-education

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2024-04-11 27.765 Default_action:pass:drop
2024-04-02 27.759