PT-2023-25428 · Funadmin · Funadmin

Leeya_Bug

·

Publicado

2023-06-22

·

Atualizado

2023-06-28

·

CVE-2023-36097

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions funadmin versions 3.3.2 through 3.3.3
Description The issue concerns insecure file upload via the plugins install.
Recommendations For versions 3.3.2 and 3.3.3, consider disabling the plugins install feature until a patch is available. Restrict access to the plugins install module to minimize the risk of exploitation.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-36097
GHSA-5M3M-Q8CQ-77G4

Produtos afetados

Funadmin