Loading HuntDB...

UniFi Video Server web interface Configuration Restore path traversal leading to local system compromise

Critical
U
Ubiquiti Inc.
Submitted None

Team Summary

Official summary from Ubiquiti Inc.

In UniFi Video Controller 3.9.3 and prior, an user with administrator privileges can restore the configuration using a specially crafted zip file. Due to the lack of validation for path transversal, the user can upload arbitrary files to arbitrary locations.

Reported by ajxchapman

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Path Traversal