BigAntSoft BigAnt Server Account Registration Bypass to File Upload RCE
Vulnerability Description
BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker can create an administrative user through the default exposed SaaS registration mechanism. Once an administrator, the attacker can upload and execute arbitrary PHP code using the "Cloud Storage Addin," leading to unauthenticated code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0364
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Cale Black
Affected Vendor
BigAntSoft
View all reports →