PT-2023-20485 · Telindus · Telindus Apsal
Alexis Pain
·
Publicado
2023-04-25
·
Atualizado
2023-05-04
·
CVE-2023-26098
CVSS v3.1
8.2
Alta
| Vetor | AC:L/AV:L/A:H/C:H/I:H/PR:L/S:C/UI:R |
Name of the Vulnerable Software and Affected Versions
Telindus Apsal version 3.14.2022.235 b
Description
An issue was discovered in the Open Document feature, allowing an attacker to upload a crafted file and execute arbitrary code.
Recommendations
For Telindus Apsal version 3.14.2022.235 b, consider disabling the Open Document feature until a patch is available to prevent the execution of arbitrary code by an attacker.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Telindus Apsal