Description

The web application uses Refinery CMS. This version of Refinery CMS depends on Dragonfly gem that has an arbitrary file read/write vulnerability. Successful exploitation of the vulnerability can result in takeover of the server.

Remediation

Upgrade to the latest version of Dragonfly gem

References

Related Vulnerabilities