PT-2023-23379 · Unknown · Ckeditor Plugin For Redmine

CVE-2023-31541

·

Publicado

2023-06-13

·

Atualizado

2025-01-03

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CKEditor plugin for Redmine version 1.2.3
Description A vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor plugin for Redmine, allowing arbitrary files to be uploaded to the server. This issue affects the ability to restrict file uploads, potentially leading to security risks.
Recommendations For version 1.2.3, consider disabling the ‘Browse and upload images’ feature until a patch is available to prevent arbitrary file uploads. Restrict access to the upload functionality to minimize the risk of exploitation.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-31541

Produtos afetados

Ckeditor Plugin For Redmine