Retour à la veille

CVE-2026-92532

Publié : 7 octobre 2026
Modifié : 7 octobre 2026
Lien officiel NVD

Description détaillée

Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the application configuration to store files in a directory accessible via the web interface. Due to the lack of proper file extension validation, an attacker could upload a malicious ASPX file and subsequently execute it on the server. A successful exploit could allow arbitrary code execution with the privileges of the account used by the web service.

Références et Patchs