Unsanitized File Upload Vulnerability in Franklin Fueling Systems TS-550 evo 2.3.0.7332 Devices

Unsanitized File Upload Vulnerability in Franklin Fueling Systems TS-550 evo 2.3.0.7332 Devices

CVE-2017-6565 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization checks are in place, an attacker can upload a malicious payload.

Learn more about our Web App Pen Testing.