PT-2023-20485 · Telindus · Telindus Apsal

Alexis Pain

·

Publicado

2023-04-25

·

Atualizado

2023-05-04

·

CVE-2023-26098

CVSS v3.1

8.2

Alta

VetorAC:L/AV:L/A:H/C:H/I:H/PR:L/S:C/UI:R
Name of the Vulnerable Software and Affected Versions Telindus Apsal version 3.14.2022.235 b
Description An issue was discovered in the Open Document feature, allowing an attacker to upload a crafted file and execute arbitrary code.
Recommendations For Telindus Apsal version 3.14.2022.235 b, consider disabling the Open Document feature until a patch is available to prevent the execution of arbitrary code by an attacker.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26098

Produtos afetados

Telindus Apsal