PT-2023-20744 · Idweb · Idweb
Jack Misiura
·
Publicado
2023-10-25
·
Atualizado
2023-10-28
·
CVE-2023-26578
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IDWeb application version 3.1.013
Description
The issue allows authenticated attackers to upload arbitrary files to the web root, including dangerous files such as ASP or ASPX, which can lead to command execution on the affected server.
Recommendations
For version 3.1.013, consider restricting access to the file upload functionality until a patch is available. As a temporary workaround, monitor the web root directory for suspicious files and remove them promptly to minimize the risk of exploitation.
Correção
Unrestricted File Upload
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Idweb