This is a security advisory detailing two vulnerabilities in Ektron CMS: unauthenticated file upload leading to RCE and XXE injection for internal scanning or file disclosure. No exploit code is provided.
Classification
Writeup 100%
Attack Type
Rce | Info Leak
Complexity
Moderate
Reliability
Theoretical
Target:Ektron CMS version 8.5.0
No auth needed
Prerequisites:Network access to the target · Ability to send HTTP requests to the target