
Cloud Vulnerability DB
A community-led vulnerabilities database
Extensis Portfolio v4.0 contains an authenticated unrestricted file upload vulnerability in the AdminFileTransferServlet component (CVE Database). The vulnerability was disclosed on January 31, 2022, and affects the file transfer functionality of the application.
The vulnerability exists in the AdminFileTransferServlet component of Extensis Portfolio v4.0, allowing authenticated users to perform unrestricted file uploads. This type of vulnerability could potentially allow attackers to upload malicious files to the server (CVE Database).
The vulnerability could potentially allow authenticated attackers to upload malicious files to the server, which could lead to unauthorized code execution or system compromise (CVE Database).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."