SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file format validation.Referenceshttps://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806https://launchpad.support.sap.com/#/notes/3071984