PT-2023-23778 · Otcms · Otcms

P0Ison

·

Publicado

2023-06-14

·

Atualizado

2024-05-17

·

CVE-2023-3241

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OTCMS versions up to 6.62
Description A vulnerability was found in OTCMS, affecting some unknown functionality of the file "/admin/read.php?mudi=announContent". The manipulation of the url argument leads to path traversal. The exploit has been disclosed to the public and may be used.
Recommendations For OTCMS versions up to 6.62, consider restricting access to the "/admin/read.php" endpoint until a patch is available. As a temporary workaround, avoid using the url argument in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-3241

Produtos afetados

Otcms