An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".Referenceshttps://gitlab.com/daniele_m/cve-list/-/blob/main/README.md