NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.Referenceshttps://www.twcert.org.tw/tw/cp-132-11116-2c1d8-1.htmlhttps://www.twcert.org.tw/en/cp-139-11120-64c52-2.html