Description
In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenance Mode setting.
Remediation
References
Related Vulnerabilities
Highcharts JS Incorrect Regular Expression Vulnerability (CVE-2018-20801)
WordPress Plugin JupiterX Core Privilege Escalation (2.0.7)
Plone CMS Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-28734)
IBM WebSEAL Use of Hard-coded Credentials Vulnerability (CVE-2018-1887)