PT-2023-20744 · Idweb · Idweb

Jack Misiura

·

Publicado

2023-10-25

·

Atualizado

2023-10-28

·

CVE-2023-26578

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IDWeb application version 3.1.013
Description The issue allows authenticated attackers to upload arbitrary files to the web root, including dangerous files such as ASP or ASPX, which can lead to command execution on the affected server.
Recommendations For version 3.1.013, consider restricting access to the file upload functionality until a patch is available. As a temporary workaround, monitor the web root directory for suspicious files and remove them promptly to minimize the risk of exploitation.

Correção

Unrestricted File Upload

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26578

Produtos afetados

Idweb