PT-2023-23379 · Unknown · Ckeditor Plugin For Redmine
CVE-2023-31541
·
Publicado
2023-06-13
·
Atualizado
2025-01-03
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CKEditor plugin for Redmine version 1.2.3
Description
A vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor plugin for Redmine, allowing arbitrary files to be uploaded to the server. This issue affects the ability to restrict file uploads, potentially leading to security risks.
Recommendations
For version 1.2.3, consider disabling the ‘Browse and upload images’ feature until a patch is available to prevent arbitrary file uploads. Restrict access to the upload functionality to minimize the risk of exploitation.
Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ckeditor Plugin For Redmine