CVE-2020-11943
Description
An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Open-AudIT 3.2.2 allows arbitrary file upload, potentially leading to remote code execution on the server.
Vulnerability
Open-AudIT version 3.2.2 contains an arbitrary file upload vulnerability. The issue exists in the file upload functionality where insufficient validation allows an attacker to upload files of any type, including server-side scripts. This affects the core upload mechanism used for device discovery logs and other features. Version 3.2.2 is the documented affected version; the fix is included in version 3.3.0 [1].
Exploitation
An attacker with network access to the Open-AudIT web interface and valid credentials (or possibly without authentication if the endpoint is exposed) can upload a malicious file, such as a PHP web shell, through the file upload form. The attacker would need to send a crafted HTTP POST request to the vulnerable upload endpoint with the malicious file payload. No additional privileges beyond the ability to reach the upload function are required.
Impact
Successful exploitation allows the attacker to achieve arbitrary file upload, which can lead to remote code execution (RCE) on the server. This gives the attacker full control over the affected system, including data exfiltration, lateral movement, and potential compromise of the entire IT infrastructure managed by Open-AudIT. The confidentiality, integrity, and availability of the system are all at risk.
Mitigation
Upgrade to Open-AudIT version 3.3.0 or later, which fixes this vulnerability as documented in the release notes [1]. As of the publication date (2020-04-29), this is the only known fix. Users still running version 3.2.2 should apply the upgrade immediately. No workarounds are provided in the reference. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Open-AudIT/Open-AudITdescription
- Range: <=3.2.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- community.opmantek.com/display/OA/Release+Notes+for+Open-AudIT+v3.3.0mitrex_refsource_MISC
- www.coresecurity.com/advisories/open-audit-multiple-vulnerabilitiesmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.