Site icon API Security Blog

PT-2025-37390

image
Name of the Vulnerable Software and Affected Versions: eCharge Hardy Barth Salia PLCC version 2.2.0 Description: A security flaw exists in eCharge Hardy Barth Salia PLCC 2.2.0 related to unrestricted upload. The issue affects processing of the file /api.php. Manipulation of the setrfidlist argument allows for unrestricted upload and may be performed remotely. The exploit has been publicly released. The vendor was contacted but did not respond. Recommendations: As a temporary workaround, consider restricting access to the /api.php file. Avoid using the setrfidlist argument in the affected API endpoint until the issue is…Read More

Exit mobile version